260681
|
- |
|
octeth
|
oempro
|
member/settings_account.php in Octeth Oempro 3.5.5.1, and possibly other versions before 4, uses cleartext to transmit a password entered in the FormValue_Password field, which makes it easier for re…
|
CWE-255
Credentials Management
|
CVE-2008-3059
|
2017-08-8 10:31 |
2008-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260682
|
- |
|
v-webmail
|
v-webmail
|
V-webmail 1.5.0 allows remote attackers to obtain sensitive information via (1) malformed input in the login page (includes/local.hooks.php) and (2) an invalid session ID, which reveals the installat…
|
CWE-200
Information Exposure
|
CVE-2008-3060
|
2017-08-8 10:31 |
2008-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260683
|
- |
|
v-webmail
|
v-webmail
|
Open redirect vulnerability in redirect.php in V-webmail 1.5.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the to parameter.
|
NVD-CWE-Other
|
CVE-2008-3061
|
2017-08-8 10:31 |
2008-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260684
|
- |
|
v-webmail
|
v-webmail
|
SQL injection vulnerability in login.php in V-webmail 1.5.0 might allow remote attackers to execute arbitrary SQL commands via the username parameter.
|
CWE-89
SQL Injection
|
CVE-2008-3063
|
2017-08-8 10:31 |
2008-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260685
|
- |
|
suse
|
opensuse
|
sudo in SUSE openSUSE 10.3 does not clear the stdin buffer when password entry times out, which might allow local users to obtain a password by reading stdin from the parent process after a sudo chil…
|
CWE-255
Credentials Management
|
CVE-2008-3067
|
2017-08-8 10:31 |
2008-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260686
|
- |
|
vim
|
vim
|
The Netrw plugin 125 in netrw.vim in Vim 7.2a.10 allows user-assisted attackers to execute arbitrary code via shell metacharacters in filenames used by the execute and system functions within the (1)…
|
CWE-78
OS Command
|
CVE-2008-3076
|
2017-08-8 10:31 |
2009-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260687
|
- |
|
opera
|
opera_browser
|
Opera before 9.51 does not properly manage memory within functions supporting the CANVAS element, which allows remote attackers to read uninitialized memory contents by using JavaScript to read a can…
|
CWE-200
Information Exposure
|
CVE-2008-3078
|
2017-08-8 10:31 |
2008-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260688
|
- |
|
opera
|
opera
|
Unspecified vulnerability in Opera before 9.51 on Windows allows attackers to execute arbitrary code via unknown vectors.
|
NVD-CWE-noinfo
|
CVE-2008-3079
|
2017-08-8 10:31 |
2008-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260689
|
- |
|
avaya
|
messaging_storage_server
|
Multiple unspecified "input validation" vulnerabilities in the Web management interface (aka Messaging Administration interface) in Avaya Message Storage Server (MSS) 3.x and 4.0, and possibly Commun…
|
CWE-20
Improper Input Validation
|
CVE-2008-3081
|
2017-08-8 10:31 |
2008-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260690
|
- |
|
commtouch
|
enterprise_anti-spam_gateway
|
Cross-site scripting (XSS) vulnerability in UPM/English/login/login.asp in Commtouch Enterprise Anti-Spam Gateway 4 and 5 allows remote attackers to inject arbitrary web script or HTML via the PARAMS…
|
CWE-79
Cross-site Scripting
|
CVE-2008-3082
|
2017-08-8 10:31 |
2008-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|