260701
|
- |
|
drupal
|
mailsave
|
Cross-site scripting (XSS) vulnerability in the Mailsave module 5.x before 5.x-3.3 and 6.x before 6.x-1.3, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via an e…
|
CWE-79
Cross-site Scripting
|
CVE-2008-4147
|
2017-08-8 10:32 |
2008-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260702
|
- |
|
drupal
|
mailhandler
|
SQL injection vulnerability in the Mailhandler module 5.x before 5.x-1.4 and 6.x before 6.x-1.4, a module for Drupal, allows remote attackers to execute arbitrary SQL commands via unspecified vectors…
|
CWE-89
SQL Injection
|
CVE-2008-4148
|
2017-08-8 10:32 |
2008-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260703
|
- |
|
drupal
|
link_to_us
|
Cross-site scripting (XSS) vulnerability in the Greg Holsclaw Link to Us module 5.x before 5.x-1.1 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via the "Link pa…
|
CWE-79
Cross-site Scripting
|
CVE-2008-4149
|
2017-08-8 10:32 |
2008-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260704
|
- |
|
drupal
|
talk
|
Cross-site scripting (XSS) vulnerability in the Talk module 5.x before 5.x-1.3 and 6.x before 6.x-1.5, a module for Drupal, allows remote authenticated users to inject arbitrary web script or HTML vi…
|
CWE-79
Cross-site Scripting
|
CVE-2008-4152
|
2017-08-8 10:32 |
2008-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260705
|
- |
|
drupal
|
talk
|
The Talk module 5.x before 5.x-1.3 and 6.x before 6.x-1.5, a module for Drupal, does not perform access checks for a node before displaying comments, which allows remote attackers to obtain sensitive…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-4153
|
2017-08-8 10:32 |
2008-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260706
|
- |
|
isc
|
bind
|
Unspecified vulnerability in ISC BIND 9.3.5-P2-W1, 9.4.2-P2-W1, and 9.5.0-P2-W1 on Windows allows remote attackers to cause a denial of service (UDP client handler termination) via unknown vectors.
|
NVD-CWE-noinfo CWE-20
Improper Input Validation
|
CVE-2008-4163
|
2017-08-8 10:32 |
2008-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260707
|
- |
|
kolab
|
kolab_groupware_server
|
admin/user/create_user.php in Kolab Groupware Server 1.0.0 places a user password in an HTTP GET request, which allows local administrators, and possibly remote attackers, to obtain cleartext passwor…
|
CWE-310
Cryptographic Issues
|
CVE-2008-4165
|
2017-08-8 10:32 |
2008-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260708
|
- |
|
rfaah
|
cars-vehicles_script
|
SQL injection vulnerability in page.php in Cars & Vehicle (aka Cars-Vehicle Script) allows remote attackers to execute arbitrary SQL commands via the lnkid parameter.
|
CWE-89
SQL Injection
|
CVE-2008-4172
|
2017-08-8 10:32 |
2008-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260709
|
- |
|
benjamin_kuz
|
dynamic_mp3_lister
|
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Dynamic MP3 Lister 2.0.1 allow remote attackers to inject arbitrary web script or HTML via the (1) currentpath, (2) invert, (3) sea…
|
CWE-79
Cross-site Scripting
|
CVE-2008-4174
|
2017-08-8 10:32 |
2008-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260710
|
- |
|
horde
|
turba_contact_manager_h3
|
Cross-site scripting (XSS) vulnerability in imp/test.php in Horde Turba Contact Manager H3 2.2.1 and other versions before 2.3.1, and possibly other Horde Project products, allows remote attackers to…
|
CWE-79
Cross-site Scripting
|
CVE-2008-4182
|
2017-08-8 10:32 |
2008-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|