260701
|
- |
|
microsoft
|
sharepoint_server
|
Microsoft SharePoint uses URLs with the same hostname and port number for a web site's primary files and individual users' uploaded files (aka attachments), which allows remote authenticated users to…
|
NVD-CWE-noinfo CWE-79
Cross-site Scripting
|
CVE-2008-5026
|
2017-08-8 10:33 |
2008-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260702
|
- |
|
libcaudio
|
libcaudio
|
Heap-based buffer overflow in the cddb_read_disc_data function in cddb.c in libcdaudio 0.99.12p2 allows remote CDDB servers to execute arbitrary code via long CDDB data.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2008-5030
|
2017-08-8 10:33 |
2008-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260703
|
- |
|
ibm
|
hardware_management_console
|
The Resource Monitoring and Control (RMC) daemon in IBM Hardware Management Console (HMC) 7 release 3.2.0 SP1 and 3.3.0 SP2 allows remote attackers to cause a denial of service (daemon crash or hang)…
|
CWE-399
Resource Management Errors
|
CVE-2008-5035
|
2017-08-8 10:33 |
2008-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260704
|
- |
|
sweex
|
ro002_router
|
Sweex RO002 Router with firmware Ts03-072 has "rdc123" as its default password for the "rdc123" account, which makes it easier for remote attackers to obtain access. NOTE: the provenance of this inf…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-5041
|
2017-08-8 10:33 |
2008-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260705
|
- |
|
isecsoft
|
anti-trojan_elite
|
Buffer overflow in Atepmon.sys in ISecSoft Anti-Trojan Elite 4.2.1 and earlier, and possibly 4.2.2, allows local users to cause a denial of service (crash) and possibly execute arbitrary code via lon…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2008-5048
|
2017-08-8 10:33 |
2008-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260706
|
- |
|
activecampaign
|
triolive
|
SQL injection vulnerability in department_offline_context.php in ActiveCampaign TrioLive before 1.58.7 allows remote attackers to execute arbitrary SQL commands via the department_id parameter to ind…
|
CWE-89
SQL Injection
|
CVE-2008-5055
|
2017-08-8 10:33 |
2008-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260707
|
- |
|
activecampaign
|
triolive
|
Cross-site scripting (XSS) vulnerability in department_offline_context.php in ActiveCampaign TrioLive before 1.58.7 allows remote attackers to inject arbitrary web script or HTML via the department_i…
|
CWE-79
Cross-site Scripting
|
CVE-2008-5056
|
2017-08-8 10:33 |
2008-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260708
|
- |
|
aspindir
|
dizi_portali
|
SQL injection vulnerability in film.asp in Yigit Aybuga Dizi Portali allows remote attackers to execute arbitrary SQL commands via the film parameter. NOTE: the provenance of this information is unk…
|
CWE-89
SQL Injection
|
CVE-2008-5057
|
2017-08-8 10:33 |
2008-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260709
|
- |
|
h\&h
|
websoccer
|
SQL injection vulnerability in liga.php in H&H WebSoccer 2.80 allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2008-5064
|
2017-08-8 10:33 |
2008-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260710
|
- |
|
htop
|
htop
|
htop 0.7 writes process names to a terminal without sanitizing non-printable characters, which might allow local users to hide processes, modify arbitrary files, or have unspecified other impact via …
|
CWE-200
Information Exposure
|
CVE-2008-5076
|
2017-08-8 10:33 |
2008-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|