257601
|
- |
|
gnu
|
coreutils
|
The default configuration of su in /etc/pam.d/su in GNU coreutils 5.2.1 allows local users to gain the privileges of a (1) locked or (2) expired account by entering the account name on the command li…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-1946
|
2017-09-29 10:30 |
2008-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257602
|
- |
|
xensource
|
xen_para_virtualized_frame_buffer
|
The backend for XenSource Xen Para Virtualized Frame Buffer (PVFB) in Xen ioemu does not properly restrict the frame buffer size, which allows attackers to cause a denial of service (crash) by mappin…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2008-1952
|
2017-09-29 10:30 |
2008-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257603
|
- |
|
webcalendar
|
web_calendar_pro
|
SQL injection vulnerability in one_day.php in Web Calendar Pro 4.1 and earlier allows remote attackers to execute arbitrary SQL commands via the user_id parameter.
|
CWE-89
SQL Injection
|
CVE-2008-1954
|
2017-09-29 10:30 |
2008-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257604
|
- |
|
easyscripts
|
tr_script_news
|
SQL injection vulnerability in news.php in Tr Script News 2.1 allows remote attackers to execute arbitrary SQL commands via the nb parameter in voir mode.
|
CWE-89
SQL Injection
|
CVE-2008-1957
|
2017-09-29 10:30 |
2008-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257605
|
- |
|
easyscripts
|
tr_script_news
|
Unrestricted file upload vulnerability in the ajout_cat mode in admin/main.php in Tr Script News 2.1 allows remote authenticated users to execute arbitrary code by uploading a file with a .php extens…
|
CWE-94
Code Injection
|
CVE-2008-1958
|
2017-09-29 10:30 |
2008-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257606
|
- |
|
php_resource
|
voice_of_web_allmyguests
|
SQL injection vulnerability in index.php in Voice Of Web AllMyGuests 0.4.1 allows remote attackers to execute arbitrary SQL commands via the AMG_id parameter in a comments action.
|
CWE-89
SQL Injection
|
CVE-2008-1961
|
2017-09-29 10:30 |
2008-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257607
|
- |
|
chimaera
|
aterr
|
Multiple directory traversal vulnerabilities in Aterr 0.9.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) class parameter to include/functions.inc.…
|
CWE-22
Path Traversal
|
CVE-2008-1962
|
2017-09-29 10:30 |
2008-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257608
|
- |
|
quate
|
grape_web_statistics
|
PHP remote file inclusion vulnerability in includes/functions.php in Quate Grape Web Statistics 0.2a allows remote attackers to execute arbitrary PHP code via a URL in the location parameter.
|
CWE-94
Code Injection
|
CVE-2008-1963
|
2017-09-29 10:30 |
2008-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257609
|
- |
|
phphq
|
phshoutbox_final
|
phShoutBox Final 1.5 and earlier only checks passwords when specified in $_POST, which allows remote attackers to gain privileges by setting the (1) phadmin cookie to admin.php, or (2) in 1.4 and ear…
|
CWE-287
Improper Authentication
|
CVE-2008-1971
|
2017-09-29 10:30 |
2008-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257610
|
- |
|
artur_sikora
|
subedit_player
|
Heap-based buffer overflow in SubEdit Player build 4056 and 4066 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long subtitle file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2008-1973
|
2017-09-29 10:30 |
2008-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|