260901
|
- |
|
dovecot
|
dovecot
|
The message parsing feature in Dovecot 1.1.4 and 1.1.5, when using the FETCH ENVELOPE command in the IMAP client, allows remote attackers to cause a denial of service (persistent crash) via an email …
|
CWE-20
Improper Input Validation
|
CVE-2008-4907
|
2017-08-8 10:32 |
2008-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260902
|
- |
|
crossfire
|
crossfire
|
maps/Info/combine.pl in CrossFire crossfire-maps 1.11.0 allows local users to overwrite arbitrary files via a symlink attack on a temporary file.
|
CWE-59
Link Following
|
CVE-2008-4908
|
2017-08-8 10:32 |
2008-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260903
|
- |
|
compact_cms
|
compact_cms
|
Cross-site request forgery (CSRF) vulnerability in CompactCMS 1.1 and earlier allows remote attackers to perform unauthorized actions as legitimate users via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2008-4909
|
2017-08-8 10:32 |
2008-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260904
|
- |
|
chattaitaliano
|
istant-replay
|
PHP remote file inclusion vulnerability in read.php in Chattaitaliano Istant-Replay allows remote attackers to execute arbitrary PHP code via a URL in the data parameter.
|
CWE-94
Code Injection
|
CVE-2008-4911
|
2017-08-8 10:32 |
2008-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260905
|
- |
|
gforge
|
gforge
|
SQL injection vulnerability in the create function in common/include/GroupJoinRequest.class in GForge 4.5 and 4.6 allows remote attackers to execute arbitrary SQL commands via the comments variable.
|
CWE-89
SQL Injection
|
CVE-2008-2381
|
2017-08-8 10:31 |
2009-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260906
|
- |
|
dotcms
|
dotcms
|
Cross-site scripting (XSS) vulnerability in search-results.dot in dotCMS 1.x allows remote attackers to inject arbitrary web script or HTML via the search_query parameter. NOTE: the provenance of th…
|
CWE-79
Cross-site Scripting
|
CVE-2008-2397
|
2017-08-8 10:31 |
2008-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260907
|
- |
|
stunnel
|
stunnel
|
Unspecified vulnerability in stunnel before 4.23, when running as a service on Windows, allows local users to gain privileges via unknown attack vectors.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-2400
|
2017-08-8 10:31 |
2008-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260908
|
- |
|
sun
|
java_active_server
|
The Admin Server in Sun Java Active Server Pages (ASP) Server before 4.0.3 allows remote attackers to append to arbitrary new or existing files via the first argument to a certain file that is includ…
|
CWE-20
Improper Input Validation
|
CVE-2008-2401
|
2017-08-8 10:31 |
2008-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260909
|
- |
|
sun
|
java_asp_server
|
The Admin Server in Sun Java Active Server Pages (ASP) Server before 4.0.3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to read pass…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-2402
|
2017-08-8 10:31 |
2008-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260910
|
- |
|
sun
|
java_asp_server
|
Multiple directory traversal vulnerabilities in unspecified ASP applications in Sun Java Active Server Pages (ASP) Server before 4.0.3 allow remote attackers to read or delete arbitrary files via a .…
|
CWE-22
Path Traversal
|
CVE-2008-2403
|
2017-08-8 10:31 |
2008-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|