260841
|
- |
|
ed_putal
|
clickbank_portal
|
Cross-site scripting (XSS) vulnerability in search.php in Ed Pudol Clickbank Portal allows remote attackers to inject arbitrary web script or HTML via the search box. NOTE: the provenance of this in…
|
CWE-79
Cross-site Scripting
|
CVE-2008-4670
|
2017-08-8 10:32 |
2008-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260842
|
- |
|
wordpress
|
wordpress_mu
|
Cross-site scripting (XSS) vulnerability in wp-admin/wp-blogs.php in Wordpress MU (WPMU) before 2.6 allows remote attackers to inject arbitrary web script or HTML via the (1) s and (2) ip_address par…
|
CWE-79
Cross-site Scripting
|
CVE-2008-4671
|
2017-08-8 10:32 |
2008-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260843
|
- |
|
goodlyrics
|
lyrics_script
|
Cross-site scripting (XSS) vulnerability in search_results.php in buymyscripts Lyrics Script allows remote attackers to inject arbitrary web script or HTML via the k parameter. NOTE: the provenance …
|
CWE-79
Cross-site Scripting
|
CVE-2008-4672
|
2017-08-8 10:32 |
2008-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260844
|
- |
|
citrix
|
access_essentials presentation_server xenapp
|
Unspecified vulnerability in Citrix XenApp (formerly Presentation Server) 4.5 Feature Pack 1 and earlier, Presentation Server 4.0, and Access Essentials 1.0, 1.5, and 2.0 allows local users to gain p…
|
NVD-CWE-noinfo CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-4676
|
2017-08-8 10:32 |
2008-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260845
|
- |
|
vim
|
netrw
|
autoload/netrw.vim (aka the Netrw Plugin) 109, 131, and other versions before 133k for Vim 7.1.266, other 7.1 versions, and 7.2 stores credentials for an FTP session, and sends those credentials when…
|
CWE-255
Credentials Management
|
CVE-2008-4677
|
2017-08-8 10:32 |
2008-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260846
|
- |
|
ibm
|
websphere_application_server
|
The HTTP_Request_Parser method in the HTTP Transport component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.31 allows remote attackers to cause a denial of service (controller 0C4 abe…
|
CWE-399
Resource Management Errors
|
CVE-2008-4678
|
2017-08-8 10:32 |
2008-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260847
|
- |
|
ibm
|
websphere_application_server
|
The Web Services Security component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.31 and 6.1 before 6.1.0.19, when Certificate Store Collections is configured to use Certificate Revoca…
|
CWE-287
Improper Authentication
|
CVE-2008-4679
|
2017-08-8 10:32 |
2008-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260848
|
- |
|
mantis
|
mantis
|
Mantis before 1.1.3 does not unset the session cookie during logout, which makes it easier for remote attackers to hijack sessions.
|
CWE-287
Improper Authentication
|
CVE-2008-4689
|
2017-08-8 10:32 |
2008-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260849
|
- |
|
ibm
|
db2
|
The Native Managed Provider for .NET component in IBM DB2 8 before FP17, 9.1 before FP6, and 9.5 before FP2, when a definer cannot maintain objects, preserves views and triggers without marking them …
|
NVD-CWE-noinfo
|
CVE-2008-4692
|
2017-08-8 10:32 |
2008-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260850
|
- |
|
ibm
|
db2
|
The SORT/LIST SERVICES component in IBM DB2 9.1 before FP6 and 9.5 before FP2 writes sensitive information to the trace output, which allows attackers to obtain sensitive information by reading "PASS…
|
CWE-200
Information Exposure
|
CVE-2008-4693
|
2017-08-8 10:32 |
2008-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|