262331
|
- |
|
cybozu
|
cybozu_dezie cybozu_garoon cybozu_office
|
Cross-site request forgery (CSRF) vulnerability in Cybozu Office 6, Cybozu Dezie before 6.0(1.0), and Cybozu Garoon 2.0.0 through 2.1.3 allows remote attackers to hijack the authentication of unspeci…
|
CWE-352
Origin Validation Error
|
CVE-2008-6744
|
2017-08-17 10:29 |
2009-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262332
|
- |
|
horde
|
turba_h3
|
Cross-site scripting (XSS) vulnerability in the contact display view in Turba Contact Manager H3 before 2.2.1 allows remote attackers to inject arbitrary web script or HTML via the contact name.
|
CWE-79
Cross-site Scripting
|
CVE-2008-6746
|
2017-08-17 10:29 |
2009-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262333
|
- |
|
dotproject
|
dotproject
|
dotProject before 2.1.2 does not properly restrict access to administrative pages, which allows remote attackers to gain privileges. NOTE: some of these details are obtained from third party informa…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-6747
|
2017-08-17 10:29 |
2009-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262334
|
- |
|
silverstripe
|
silverstripe
|
SQL injection vulnerability in SilverStripe before 2.2.2 allows remote attackers to execute arbitrary SQL commands via unspecified vectors related to AjaxUniqueTextField.
|
CWE-89
SQL Injection
|
CVE-2008-6753
|
2017-08-17 10:29 |
2009-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262335
|
- |
|
zoneminder
|
zoneminder
|
ZoneMinder 1.23.3 on Fedora 10 sets the ownership of /etc/zm.conf to the apache user account, and sets the permissions to 0600, which makes it easier for remote attackers to modify this file by acces…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-6755
|
2017-08-17 10:29 |
2009-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262336
|
- |
|
zoneminder
|
zoneminder
|
ZoneMinder 1.23.3 on Gentoo Linux uses 0644 permissions for /etc/zm.conf, which allows local users to obtain the database username and password by reading this file.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-6756
|
2017-08-17 10:29 |
2009-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262337
|
- |
|
wordpress
|
wordpress
|
Open redirect vulnerability in wp-admin/upgrade.php in WordPress, probably 2.6.x, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the backto…
|
CWE-59
Link Following
|
CVE-2008-6762
|
2017-08-17 10:29 |
2009-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262338
|
- |
|
hypersilence
|
silentum_loginsys
|
Cross-site scripting (XSS) vulnerability in login.php in Silentum LoginSys 1.0.0 allows remote attackers to inject arbitrary web script or HTML via the message parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2008-6764
|
2017-08-17 10:29 |
2009-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262339
|
- |
|
wordpress
|
wordpress
|
wp-admin/upgrade.php in WordPress, probably 2.6.x, allows remote attackers to upgrade the application, and possibly cause a denial of service (application outage), via a direct request.
|
NVD-CWE-noinfo
|
CVE-2008-6767
|
2017-08-17 10:29 |
2009-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262340
|
- |
|
peterselie
|
yourplace
|
internettoolbar/edit.php in YourPlace 1.0.2 and earlier does not end execution when an invalid username is detected, which allows remote attackers to bypass intended restrictions and edit toolbar set…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-6774
|
2017-08-17 10:29 |
2009-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|