260741
|
- |
|
anelectron
|
advanced_electron_forum
|
Cross-site scripting (XSS) vulnerability in Advanced Electron Forum (AEF) 1.0.6 allows remote attackers to inject arbitrary web script or HTML via the beg parameter in a members action to index.php.
|
CWE-79
Cross-site Scripting
|
CVE-2008-1983
|
2017-08-8 10:30 |
2008-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260742
|
- |
|
digital_hive
|
digitalhive
|
Cross-site scripting (XSS) vulnerability in base.php in DigitalHive 2.0 RC2 allows remote attackers to inject arbitrary web script or HTML via the mt parameter, possibly related to membres.php.
|
CWE-79
Cross-site Scripting
|
CVE-2008-1985
|
2017-08-8 10:30 |
2008-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260743
|
- |
|
pixel_motion
|
pixel_motion_blog
|
Cross-site scripting (XSS) vulnerability in liste_article.php in Blog Pixel Motion (aka PixelMotion) allows remote attackers to inject arbitrary web script or HTML via the jours parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2008-1986
|
2017-08-8 10:30 |
2008-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260744
|
- |
|
encaps
|
encapsgallery
|
Cross-site scripting (XSS) vulnerability in search.php in EncapsGallery 2.0.2 allows remote attackers to inject arbitrary web script or HTML via the search parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2008-1987
|
2017-08-8 10:30 |
2008-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260745
|
- |
|
encaps
|
encapsgallery
|
Unrestricted file upload vulnerability in the file_upload function in core/misc.class.php in EncapsGallery 2.0.2 allows remote authenticated administrators to upload and execute arbitrary PHP files b…
|
CWE-20
Improper Input Validation
|
CVE-2008-1988
|
2017-08-8 10:30 |
2008-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260746
|
- |
|
ahmed_abdel-hamid_mohamed
|
acon
|
Multiple stack-based buffer overflows in (a) acon.c, (b) menu.c, and (c) child.c in Acon 1.0.5-5 through 1.0.5-7 allow local users to execute arbitrary code via (1) a long HOME environment variable o…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2008-1994
|
2017-08-8 10:30 |
2008-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260747
|
- |
|
licq
|
licq
|
licq before 1.3.6 allows remote attackers to cause a denial of service (file-descriptor exhaustion and application crash) via a large number of connections.
|
CWE-399
Resource Management Errors
|
CVE-2008-1996
|
2017-08-8 10:30 |
2008-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260748
|
- |
|
licq
|
licq
|
More information located: http://www.securityfocus.com/bid/28679/info
|
CWE-399
Resource Management Errors
|
CVE-2008-1996
|
2017-08-8 10:30 |
2008-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260749
|
- |
|
national_rail_enquiries
|
national_rail_enquiries_live_departure_boards
|
Cross-site scripting (XSS) vulnerability in the National Rail Enquiries Live Departure Boards gadget before 1.1 allows remote National Rail Enquiries servers or man-in-the-middle attackers to inject …
|
CWE-79
Cross-site Scripting
|
CVE-2008-2011
|
2017-08-8 10:30 |
2008-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260750
|
- |
|
lhaplus
|
lhaplus
|
Heap-based buffer overflow in Lhaplus before 1.57 allows remote attackers to execute arbitrary code via a long comment field in a ZOO archive.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2008-2021
|
2017-08-8 10:30 |
2008-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|