260931
|
- |
|
typo3
|
kj_imagelightbox2
|
Cross-site scripting (XSS) vulnerability in the KJ Image Lightbox 2 (aka kj_imagelightbox2) extension 1.4.2 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via un…
|
CWE-79
Cross-site Scripting
|
CVE-2008-2490
|
2017-08-8 10:31 |
2008-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260932
|
- |
|
mambo-foundation
|
mambo
|
CRLF injection vulnerability in Mambo before 4.6.4 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
|
CWE-94
Code Injection
|
CVE-2008-2497
|
2017-08-8 10:31 |
2008-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260933
|
- |
|
mambo-foundation
|
mambo
|
Multiple SQL injection vulnerabilities in index.php in Mambo before 4.6.4, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) articleid and (2) mc…
|
CWE-89
SQL Injection
|
CVE-2008-2498
|
2017-08-8 10:31 |
2008-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260934
|
- |
|
mambo
|
mostlyce
|
Cross-site scripting (XSS) vulnerability in the MOStlyContent Editor (MOStlyCE) component before 3.0 for Mambo allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2008-2500
|
2017-08-8 10:31 |
2008-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260935
|
- |
|
emule
|
x_ray
|
Unspecified vulnerability in the web server in eMule X-Ray before 1.4 allows remote attackers to trigger memory corruption via unknown attack vectors.
|
NVD-CWE-noinfo CWE-399
Resource Management Errors
|
CVE-2008-2502
|
2017-08-8 10:31 |
2008-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260936
|
- |
|
sourceforge
|
emule_x-ray
|
Buffer overflow in Uploadlist in eMule X-Ray before 1.4 has unknown impact and remote attack vectors.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2008-2503
|
2017-08-8 10:31 |
2008-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260937
|
- |
|
tr_script_news
|
tr_script_news
|
Cross-site scripting (XSS) vulnerability in news.php in Tr Script News 2.1 allows remote attackers to inject arbitrary web script or HTML via the "nb" parameter in voir mode.
|
CWE-79
Cross-site Scripting
|
CVE-2008-2508
|
2017-08-8 10:31 |
2008-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260938
|
- |
|
symantec
|
backupexec_system_recovery
|
Directory traversal vulnerability in Symantec Backup Exec System Recovery Manager 7.x before 7.0.4 and 8.x before 8.0.2 allows remote attackers to read arbitrary files via unspecified vectors.
|
CWE-22
Path Traversal
|
CVE-2008-2512
|
2017-08-8 10:31 |
2008-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260939
|
- |
|
libpam-pgsql
|
libpam-pgsql
|
pam_sm_authenticate in pam_pgsql.c in libpam-pgsql 0.6.3 does not properly consider operator precedence when evaluating the success of a pam_get_pass function call, which allows local users to gain p…
|
CWE-287
Improper Authentication
|
CVE-2008-2516
|
2017-08-8 10:31 |
2008-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260940
|
- |
|
sarab
|
sarab
|
The sarab.sh script in SaraB before 0.2.4 places the dar program's encryption key on the command line, which allows local users to obtain sensitive information by listing the process.
|
CWE-200
Information Exposure
|
CVE-2008-2517
|
2017-08-8 10:31 |
2008-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|