261251
|
- |
|
sun
|
solaris
|
Unspecified vulnerability in xscreensaver in Sun Solaris 10 Java Desktop System (JDS), when using the GNOME On-Screen Keyboard (GOK), allows local users to bypass authentication via unknown vectors t…
|
CWE-287
Improper Authentication
|
CVE-2008-1356
|
2017-08-8 10:30 |
2008-03-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261252
|
- |
|
invision_power_services
|
invision_power_board
|
Cross-site scripting (XSS) vulnerability in Invision Power Board (IPB or IP.Board) 2.3.4 before 2008-03-13 allows remote attackers to inject arbitrary web script or HTML via nested BBCodes, a differe…
|
CWE-79
Cross-site Scripting
|
CVE-2008-1359
|
2017-08-8 10:30 |
2008-03-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261253
|
- |
|
nagios
|
nagios
|
Cross-site scripting (XSS) vulnerability in Nagios before 2.11 allows remote attackers to inject arbitrary web script or HTML via unknown vectors to unspecified CGI scripts, a different issue than CV…
|
CWE-79
Cross-site Scripting
|
CVE-2008-1360
|
2017-08-8 10:30 |
2008-03-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261254
|
- |
|
wildmary
|
yap_blog
|
PHP remote file inclusion vulnerability in index.php in wildmary Yap Blog 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter. NOTE: the provenance of this info…
|
CWE-94
Code Injection
|
CVE-2008-1370
|
2017-08-8 10:30 |
2008-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261255
|
- |
|
drake_team
|
drake_cms
|
Absolute path traversal vulnerability in install/index.php in Drake CMS 0.4.11 RC8 allows remote attackers to read and execute arbitrary files via a full pathname in the d_root parameter. NOTE: the …
|
CWE-22
Path Traversal
|
CVE-2008-1371
|
2017-08-8 10:30 |
2008-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261256
|
- |
|
drake_team
|
drake_cms
|
CVE description identifies vulnerability as remote attacker, but both links describe vulnerability as local-file inclusion.
|
CWE-22
Path Traversal
|
CVE-2008-1371
|
2017-08-8 10:30 |
2008-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261257
|
- |
|
zoneminder
|
zoneminder
|
ZoneMinder before 1.23.3 allows remote authenticated users, and possibly unauthenticated attackers in some installations, to execute arbitrary commands via shell metacharacters in a crafted URL.
|
CWE-94
Code Injection
|
CVE-2008-1381
|
2017-08-8 10:30 |
2008-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261258
|
- |
|
zoneminder
|
zoneminder
|
The following link contains patch information: http://www.zoneminder.com/wiki/index.php/1.23.2_Patches
|
CWE-94
Code Injection
|
CVE-2008-1381
|
2017-08-8 10:30 |
2008-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261259
|
- |
|
gentoo
|
linux
|
The docert function in ssl-cert.eclass, when used by src_compile or src_install on Gentoo Linux, stores the SSL key in a binpkg, which allows local users to extract the key from the binpkg, and cause…
|
CWE-310
Cryptographic Issues
|
CVE-2008-1383
|
2017-08-8 10:30 |
2008-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261260
|
- |
|
checkpoint
|
check_point_vpn-1_pro vpn-1 vpn-1_firewall-1 vpn-1_power_utm vpn-1_power_utm_with_ngx
|
Check Point VPN-1 Power/UTM, with NGX R60 through R65 and NG AI R55 software, allows remote authenticated users to cause a denial of service (site-to-site VPN tunnel outage), and possibly intercept n…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-1397
|
2017-08-8 10:30 |
2008-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|