261991
|
- |
|
mozilo
|
mozilocms
|
Session fixation vulnerability in moziloCMS 1.10.2 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.
|
CWE-287
Improper Authentication
|
CVE-2008-6128
|
2017-08-17 10:29 |
2009-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261992
|
- |
|
mozilo
|
mozilowiki
|
Directory traversal vulnerability in print.php in moziloWiki 1.0.1 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter.
|
CWE-22
Path Traversal
|
CVE-2008-6129
|
2017-08-17 10:29 |
2009-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261993
|
- |
|
mozilo
|
mozilowiki
|
Cross-site scripting (XSS) vulnerability in index.php in moziloWiki 1.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) action and (2) page parameters.
|
CWE-79
Cross-site Scripting
|
CVE-2008-6130
|
2017-08-17 10:29 |
2009-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261994
|
- |
|
mozilo
|
mozilowiki
|
Session fixation vulnerability in moziloWiki 1.0.1 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.
|
CWE-287
Improper Authentication
|
CVE-2008-6131
|
2017-08-17 10:29 |
2009-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261995
|
- |
|
drupal
|
everyblog
|
SQL injection vulnerability in EveryBlog 5.x and 6.x, a module for Drupal, allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
|
CWE-89
SQL Injection
|
CVE-2008-6134
|
2017-08-17 10:29 |
2009-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261996
|
- |
|
drupal
|
everyblog
|
Cross-site scripting (XSS) vulnerability in EveryBlog 5.x and 6.x, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2008-6135
|
2017-08-17 10:29 |
2009-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261997
|
- |
|
drupal
|
everyblog
|
Unspecified vulnerability in EveryBlog 5.x and 6.x, a module for Drupal, allows remote attackers to gain privileges as another user or an administrator via unknown attack vectors.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-6136
|
2017-08-17 10:29 |
2009-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261998
|
- |
|
drupal
|
everyblog
|
EveryBlog 5.x and 6.x, a module for Drupal, allows remote attackers to bypass access restrictions via unknown vectors.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-6137
|
2017-08-17 10:29 |
2009-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261999
|
- |
|
avaya
|
one-x
|
Unspecified vulnerability in the Session Initiation Protocol (SIP) implementation in Avaya one-X Desktop Edition 2.1.0.78 allows remote attackers to cause a denial of service (crash) via unspecified …
|
NVD-CWE-noinfo
|
CVE-2008-6140
|
2017-08-17 10:29 |
2009-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262000
|
- |
|
avaya
|
ip_soft_phone
|
Unspecified vulnerability in Avaya IP Softphone 6.0 SP4 and 6.01.85 allows remote attackers to cause a denial of service (crash) via a large amount of H.323 data.
|
CWE-399
Resource Management Errors
|
CVE-2008-6141
|
2017-08-17 10:29 |
2009-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|