257131
|
- |
|
mozilla
|
firefox
|
Mozilla Firefox 2.0.0.14, and other versions before 2.0.0.17, allows remote attackers to bypass cross-site scripting (XSS) protection mechanisms and conduct XSS attacks via HTML-escaped low surrogate…
|
CWE-79
Cross-site Scripting
|
CVE-2008-4066
|
2017-09-29 10:31 |
2008-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257132
|
- |
|
mozilla
|
firefox seamonkey
|
The XBM decoder in Mozilla Firefox before 2.0.0.17 and SeaMonkey before 1.1.12 allows remote attackers to read uninitialized memory, and possibly obtain sensitive information in opportunistic circums…
|
CWE-200
Information Exposure
|
CVE-2008-4069
|
2017-09-29 10:31 |
2008-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257133
|
- |
|
mozilla
|
seamonkey thunderbird
|
Heap-based buffer overflow in Mozilla Thunderbird before 2.0.0.17 and SeaMonkey before 1.1.12 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary co…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2008-4070
|
2017-09-29 10:31 |
2008-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257134
|
- |
|
zanfi_solutions
|
autodealers_cms_autonline
|
SQL injection vulnerability in index.php in Zanfi Autodealers CMS AutOnline allows remote attackers to execute arbitrary SQL commands via the pageid parameter in a DBpAGE action.
|
CWE-89
SQL Injection
|
CVE-2008-4073
|
2017-09-29 10:31 |
2008-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257135
|
- |
|
zanfi_solutions
|
autodealers_cms_autonline
|
SQL injection vulnerability in index.php in Zanfi Autodealers CMS AutOnline allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action.
|
CWE-89
SQL Injection
|
CVE-2008-4074
|
2017-09-29 10:31 |
2008-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257136
|
- |
|
dino
|
d-iscussion_board
|
Directory traversal vulnerability in index.php in D-iscussion Board 3.01 allows remote attackers to read arbitrary files via a .. (dot dot) in the topic parameter.
|
CWE-22
Path Traversal
|
CVE-2008-4075
|
2017-09-29 10:31 |
2008-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257137
|
- |
|
stash
|
stash
|
admin/login.php in Stash 1.0.3 allows remote attackers to bypass authentication and gain administrative access by setting a bsm cookie.
|
CWE-287
Improper Authentication
|
CVE-2008-4081
|
2017-09-29 10:31 |
2008-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257138
|
- |
|
brim-project
|
brim
|
SQL injection vulnerability in the Tasks plugin in Brim 2.0.0, when magic_quotes_gpc is disabled, allows remote authenticated users to execute arbitrary SQL commands via an arbitrary field in a searc…
|
CWE-89
SQL Injection
|
CVE-2008-4082
|
2017-09-29 10:31 |
2008-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257139
|
- |
|
brim-project
|
brim
|
Cross-site scripting (XSS) vulnerability in the Bookmarks plugin in Brim 2.0 allows remote authenticated users to inject arbitrary web script or HTML via the name parameter in an addItemPost action t…
|
CWE-79
Cross-site Scripting
|
CVE-2008-4083
|
2017-09-29 10:31 |
2008-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257140
|
- |
|
myiosoft
|
easyclassifields
|
SQL injection vulnerability in staticpages/easyclassifields/index.php in MyioSoft EasyClassifields 3.0 allows remote attackers to execute arbitrary SQL commands via the go parameter in a browse actio…
|
CWE-89
SQL Injection
|
CVE-2008-4084
|
2017-09-29 10:31 |
2008-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|