260691
|
- |
|
joomla
|
joomla
|
JRequest in Joomla! 1.5 before 1.5.7 does not sanitize variables that were set with JRequest::setVar, which allows remote attackers to conduct "variable injection" attacks and have unspecified other …
|
CWE-20
Improper Input Validation
|
CVE-2008-4105
|
2017-08-8 10:32 |
2008-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260692
|
- |
|
python_software_foundation
|
python
|
Tools/faqwiz/move-faqwiz.sh (aka the generic FAQ wizard moving tool) in Python 2.4.5 might allow local users to overwrite arbitrary files via a symlink attack on a tmp$RANDOM.tmp temporary file. NOT…
|
CWE-59
Link Following
|
CVE-2008-4108
|
2017-08-8 10:32 |
2008-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260693
|
- |
|
ibm
|
websphere_application_server
|
Unspecified vulnerability in Servlet Engine/Web Container in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.31 and 6.1 before 6.1.0.19, when the FileServing feature is enabled, has unknown…
|
NVD-CWE-noinfo
|
CVE-2008-4111
|
2017-08-8 10:32 |
2008-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260694
|
- |
|
sun
|
management_center
|
Unspecified vulnerability in a web page in the PRM module in Sun Management Center (SunMC) 3.6.1 and 4.0 allows remote attackers to cause a denial of service (memory consumption) via unspecified vect…
|
NVD-CWE-noinfo
|
CVE-2008-4117
|
2017-08-8 10:32 |
2008-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260695
|
- |
|
high_norm
|
sound_master_2nd
|
Cross-site scripting (XSS) vulnerability in High Norm Sound Master 2nd 1.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2008-4118
|
2017-08-8 10:32 |
2008-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260696
|
- |
|
phpbb
|
phpbb
|
The search function in phpBB 2.x provides a search_id value that leaks the state of PHP's PRNG, which allows remote attackers to obtain potentially sensitive information, as demonstrated by a cross-a…
|
NVD-CWE-noinfo CWE-200
Information Exposure
|
CVE-2008-4125
|
2017-08-8 10:32 |
2008-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260697
|
- |
|
gallery
|
gallery
|
Gallery before 1.5.9, and 2.x before 2.2.6, does not properly handle ZIP archives containing symbolic links, which allows remote authenticated users to conduct directory traversal attacks and read ar…
|
CWE-22
Path Traversal
|
CVE-2008-4129
|
2017-08-8 10:32 |
2008-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260698
|
- |
|
gallery
|
gallery
|
Cross-site scripting (XSS) vulnerability in Gallery 2.x before 2.2.6 allows remote attackers to inject arbitrary web script or HTML via a crafted Flash animation, related to the ability of the animat…
|
CWE-79
Cross-site Scripting
|
CVE-2008-4130
|
2017-08-8 10:32 |
2008-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260699
|
- |
|
componentone
|
vsflexgrid
|
Stack-based buffer overflow in the VSFlexGrid.VSFlexGridL ActiveX control in ComponentOne VSFlexGrid 7.0.1.151 and 8.0.20072.239 allows remote attackers to execute arbitrary code via a long first arg…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2008-4132
|
2017-08-8 10:32 |
2008-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260700
|
- |
|
razorecommerce
|
shopping_cart
|
SQL injection vulnerability in category_search.php in RazorCommerce Shopping Cart allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2008-4143
|
2017-08-8 10:32 |
2008-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|