260711
|
- |
|
webcms
|
webcms_portal_edition
|
Cross-site scripting (XSS) vulnerability in index.php in webCMS Portal Edition allows remote attackers to inject arbitrary web script or HTML via the patron parameter. NOTE: the provenance of this i…
|
CWE-79
Cross-site Scripting
|
CVE-2008-4184
|
2017-08-8 10:32 |
2008-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260712
|
- |
|
webcms
|
webcms_portal_edition
|
SQL injection vulnerability in index.php in webCMS Portal Edition allows remote attackers to execute arbitrary SQL commands via the id_doc parameter. NOTE: the provenance of this information is unkn…
|
CWE-89
SQL Injection
|
CVE-2008-4186
|
2017-08-8 10:32 |
2008-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260713
|
- |
|
typo3
|
secure_directory
|
Unspecified vulnerability in the TYPO3 Secure Directory (kw_secdir) extension before 1.0.2 allows remote attackers to execute arbitrary code via unknown vectors related to "injection of control chara…
|
NVD-CWE-noinfo CWE-94
Code Injection
|
CVE-2008-4188
|
2017-08-8 10:32 |
2008-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260714
|
- |
|
emacspeak_inc
|
emacspeak
|
extract-table.pl in Emacspeak 26 and 28 allows local users to overwrite arbitrary files via a symlink attack on the extract-table.csv temporary file.
|
CWE-59
Link Following
|
CVE-2008-4191
|
2017-08-8 10:32 |
2008-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260715
|
- |
|
redhat
|
cman
|
The pserver_shutdown function in fence_egenera in cman 2.20080629 and 2.20080801 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/eglog temporary file.
|
CWE-59
Link Following
|
CVE-2008-4192
|
2017-08-8 10:32 |
2008-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260716
|
- |
|
pdnsd
|
pdnsd
|
The p_exec_query function in src/dns_query.c in pdnsd before 1.2.7-par allows remote attackers to cause a denial of service (daemon crash) via a long DNS reply with many entries in the answer section…
|
CWE-399
Resource Management Errors
|
CVE-2008-4194
|
2017-08-8 10:32 |
2008-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260717
|
- |
|
opera
|
opera_browser
|
Opera before 9.52 does not properly restrict the ability of a framed web page to change the address associated with a different frame, which allows remote attackers to trigger the display of an arbit…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-4195
|
2017-08-8 10:32 |
2008-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260718
|
- |
|
opera
|
opera_browser
|
Opera before 9.52, when rendering an http page that has loaded an https page into a frame, displays a padlock icon and offers a security information dialog reporting a secure connection, which might …
|
NVD-CWE-Other
|
CVE-2008-4198
|
2017-08-8 10:32 |
2008-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260719
|
- |
|
opera
|
opera_browser
|
Opera before 9.52 does not prevent use of links from web pages to feed source files on the local disk, which might allow remote attackers to determine the validity of local filenames via vectors invo…
|
CWE-200
Information Exposure
|
CVE-2008-4199
|
2017-08-8 10:32 |
2008-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260720
|
- |
|
opera
|
opera_browser
|
Opera before 9.52 does not ensure that the address field of a news feed represents the feed's actual URL, which allows remote attackers to change this field to display the URL of a page containing we…
|
CWE-20
Improper Input Validation
|
CVE-2008-4200
|
2017-08-8 10:32 |
2008-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|