260461
|
- |
|
citrix
|
presentation_server_client
|
Citrix Presentation Server Client for Windows before 10.200 does not clear "credential information" from process memory in unspecified circumstances, which might allow local users to gain privileges.
|
CWE-200
Information Exposure
|
CVE-2008-6561
|
2017-08-17 10:29 |
2009-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260462
|
- |
|
jax_scripts
|
jax_linklists
|
Cross-site scripting (XSS) vulnerability in jax_linklists.php in Jack (tR) Jax LinkLists 1.00 allows remote attackers to inject arbitrary web script or HTML via the cat parameter. NOTE: the provenan…
|
CWE-79
Cross-site Scripting
|
CVE-2008-6562
|
2017-08-17 10:29 |
2009-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260463
|
- |
|
nortel
|
communication_server_1000 unistim_protocol
|
Nortel UNIStim protocol, as used in Communication Server 1000 and other products, uses predictable sequence numbers, which allows remote attackers to hijack sessions via sniffing or brute force attac…
|
NVD-CWE-Other
|
CVE-2008-6564
|
2017-08-17 10:29 |
2009-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260464
|
- |
|
yehe
|
yehe
|
Unrestricted file upload vulnerability in Yehe 2.0 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the fi…
|
CWE-20
Improper Input Validation
|
CVE-2008-6568
|
2017-08-17 10:29 |
2009-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260465
|
- |
|
cybozu
|
garoon
|
Session fixation vulnerability in Cybozu Garoon 2.0.0 through 2.1.3 allows remote attackers to hijack web sessions via the session ID in the login page.
|
CWE-287
Improper Authentication
|
CVE-2008-6569
|
2017-08-17 10:29 |
2009-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260466
|
- |
|
cybozu
|
garoon
|
Cross-site scripting (XSS) vulnerability in the RSS reader in Cybozu Garoon 2.0.0 through 2.1.3 allows remote attackers to inject arbitrary web script or HTML via a crafted RSS feed.
|
CWE-79
Cross-site Scripting
|
CVE-2008-6570
|
2017-08-17 10:29 |
2009-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260467
|
- |
|
avaya
|
communication_manager
|
Multiple SQL injection vulnerabilities in Avaya SIP Enablement Services (SES) in Avaya Avaya Communication Manager 3.x, 4.0, and 5.0 (1) allow remote attackers to execute arbitrary SQL commands via u…
|
CWE-89
SQL Injection
|
CVE-2008-6573
|
2017-08-17 10:29 |
2009-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260468
|
- |
|
avaya
|
communication_manager
|
Unspecified vulnerability in SIP Enablement Services (SES) in Avaya Communication Manager 3.1.x and 4.x allows remote attackers to gain privileges and cause a denial of service via unknown vectors re…
|
NVD-CWE-noinfo
|
CVE-2008-6574
|
2017-08-17 10:29 |
2009-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260469
|
- |
|
avaya
|
communication_manager
|
Unspecified vulnerability in the SIP server in SIP Enablement Services (SES) in Avaya Communication Manager 3.1.x and 4.x allows remote authenticated users to cause a denial of service (resource cons…
|
NVD-CWE-noinfo
|
CVE-2008-6575
|
2017-08-17 10:29 |
2009-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260470
|
- |
|
nortel
|
cs1000
|
Unspecified vulnerability in the "session limitation technique" in the FTP service on Nortel Communications Server 1000 (CS1K) 4.50.x, when running on VGMC or signaling nodes, allows remote attackers…
|
NVD-CWE-noinfo
|
CVE-2008-6576
|
2017-08-17 10:29 |
2009-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|