260741
|
- |
|
outshine
|
phportfolio
|
SQL injection vulnerability in photo.php in PHPortfolio, possibly 1.3, allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2008-4348
|
2017-08-8 10:32 |
2008-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260742
|
- |
|
s0nic
|
paranews
|
Multiple cross-site scripting (XSS) vulnerabilities in news.php in s0nic Paranews 3.4 allow remote attackers to inject arbitrary web script or HTML via the (1) id or (2) page parameter in a details a…
|
CWE-79
Cross-site Scripting
|
CVE-2008-4349
|
2017-08-8 10:32 |
2008-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260743
|
- |
|
spaw_editor
|
spaw_php
|
Unspecified vulnerability in class/theme.class.php in SPAW Editor PHP Edition before 2.0.8.1 has unknown impact and attack vectors, probably related to directory traversal sequences in the theme name.
|
NVD-CWE-noinfo CWE-20
Improper Input Validation
|
CVE-2008-4358
|
2017-08-8 10:32 |
2008-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260744
|
- |
|
siteman
|
siteman
|
Cross-site scripting (XSS) vulnerability in search.php in Siteman 1.1.11 and earlier allows remote attackers to inject arbitrary web script or HTML via unknown vectors. NOTE: the provenance of this …
|
CWE-79
Cross-site Scripting
|
CVE-2008-4365
|
2017-08-8 10:32 |
2008-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260745
|
- |
|
apple
|
mac_os_x
|
The default configuration of Java 1.5 on Apple Mac OS X 10.5.4 and 10.5.5 contains a jurisdiction policy that limits Java Cryptography Extension (JCE) key sizes to 128 bits, which makes it easier for…
|
CWE-310
Cryptographic Issues
|
CVE-2008-4368
|
2017-08-8 10:32 |
2008-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260746
|
- |
|
iseemedia mgi_software roxio
|
lpviewer
|
Multiple stack-based buffer overflows in MGI Software LPViewer ActiveX control (LPControl.dll), as acquired by Roxio and iseemedia, allow remote attackers to execute arbitrary code via the (1) url, (…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2008-4384
|
2017-08-8 10:32 |
2008-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260747
|
- |
|
systemrequirementslab
|
system_requirements_lab
|
Husdawg, LLC Systems Requirements Lab 3, as used by Instant Expert Analysis, allows remote attackers to force the download and execution of arbitrary programs via by specifiying a malicious website a…
|
CWE-94
Code Injection
|
CVE-2008-4385
|
2017-08-8 10:32 |
2008-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260748
|
- |
|
sap simba_technologies
|
sapgui mdrmsap_activex_control
|
Unspecified vulnerability in the Simba MDrmSap ActiveX control in mdrmsap.dll in SAP SAPgui allows remote attackers to execute arbitrary code via unknown vectors involving instantiation by Internet E…
|
CWE-94
Code Injection
|
CVE-2008-4387
|
2017-08-8 10:32 |
2008-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260749
|
- |
|
sap simba_technologies
|
sapgui mdrmsap_activex_control
|
Patch Information (SAP Login Required) = http://service.sap.com/sap/support/notes/1142431
|
CWE-94
Code Injection
|
CVE-2008-4387
|
2017-08-8 10:32 |
2008-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260750
|
- |
|
d.j.bernstein
|
djbdns
|
dnscache in Daniel J. Bernstein djbdns 1.05 does not prevent simultaneous identical outbound DNS queries, which makes it easier for remote attackers to spoof DNS responses, as demonstrated by a spoof…
|
CWE-362
Race Condition
|
CVE-2008-4392
|
2017-08-8 10:32 |
2009-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|