261651
|
- |
|
refbase
|
refbase
|
Cross-site scripting (XSS) vulnerability in refbase before 0.9.5 allows remote attackers to inject arbitrary web script or HTML via the headerMsg parameter to (1) show.php and (2) search.php. NOTE: …
|
CWE-79
Cross-site Scripting
|
CVE-2008-6400
|
2017-08-17 10:29 |
2009-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261652
|
- |
|
extrosoft
|
thyme
|
Cross-site scripting (XSS) vulnerability in add_calendars.php in eXtrovert Software Thyme 1.3 allows remote attackers to inject arbitrary web script or HTML via the callback parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2008-6404
|
2017-08-17 10:29 |
2009-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261653
|
- |
|
vignette
|
vignette_content_management
|
Unspecified vulnerability in Vignette Content Management 7.3.0.5, 7.3.1, 7.3.1.1, 7.4, and 7.5 allows "low privileged" users to gain administrator privileges via unknown attack vectors.
|
NVD-CWE-noinfo
|
CVE-2008-6412
|
2017-08-17 10:29 |
2009-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261654
|
- |
|
ticklespace
|
answers_module
|
Cross-site scripting (XSS) vulnerability in the Answers module 5.x-1.x-dev and possibly other 5.x versions, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via a S…
|
CWE-79
Cross-site Scripting
|
CVE-2008-6413
|
2017-08-17 10:29 |
2009-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261655
|
- |
|
youngzsoft
|
ccproxy
|
Buffer overflow in YoungZSoft CCProxy 6.5 might allow remote attackers to execute arbitrary code via a CONNECTION request with a long hostname.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2008-6415
|
2017-08-17 10:29 |
2009-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261656
|
- |
|
greensql
|
greensql-console
|
Multiple cross-site scripting (XSS) vulnerabilities in GreenSQL-Console before 0.3.5 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to "internal pages."
|
CWE-79
Cross-site Scripting
|
CVE-2008-6416
|
2017-08-17 10:29 |
2009-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261657
|
- |
|
greensql
|
greensql-console
|
Unspecified vulnerability in GreenSQL-Console before 0.3.5 allows attackers to obtain the "installation directory" via unknown vectors.
|
NVD-CWE-noinfo
|
CVE-2008-6417
|
2017-08-17 10:29 |
2009-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261658
|
- |
|
jun_sota
|
ffftp
|
Directory traversal vulnerability in FFFTP 1.96b allows remote FTP servers to create or overwrite arbitrary files via a response to an FTP LIST command with a filename that contains a .. (dot dot).
|
CWE-22
Path Traversal
|
CVE-2008-6424
|
2017-08-17 10:29 |
2009-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261659
|
- |
|
kayalang
|
kaya
|
The CGI framework in Kaya 0.4.0 allows remote attackers to inject arbitrary HTTP headers and conduct cross-site scripting (XSS) attacks via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2008-6428
|
2017-08-17 10:29 |
2009-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261660
|
- |
|
blueriver
|
sava_cms
|
Cross-site scripting (XSS) vulnerability in index.cfm in Blue River Interactive Group Sava CMS before 5.0.122 allows remote attackers to inject arbitrary web script or HTML via the keywords parameter…
|
CWE-79
Cross-site Scripting
|
CVE-2008-6433
|
2017-08-17 10:29 |
2009-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|