260721
|
- |
|
wordpress
|
wordpress
|
WordPress 2.6.3 relies on the REQUEST superglobal array in certain dangerous situations, which makes it easier for remote attackers to conduct delayed and persistent cross-site request forgery (CSRF)…
|
CWE-352
Origin Validation Error
|
CVE-2008-5113
|
2017-08-8 10:33 |
2008-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260722
|
- |
|
sun
|
java_system_identity_manager
|
Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager 6.0 through 6.0 SP4, 7.0, and 7.1 allow remote attackers to inject arbitrary web script or HTML via unspecified…
|
CWE-79
Cross-site Scripting
|
CVE-2008-5114
|
2017-08-8 10:33 |
2008-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260723
|
- |
|
sun
|
java_system_identity_manager
|
Open redirect vulnerability in Sun Java System Identity Manager 6.0 through 6.0 SP4, 7.0, and 7.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via uns…
|
CWE-20
Improper Input Validation
|
CVE-2008-5117
|
2017-08-8 10:33 |
2008-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260724
|
- |
|
sun
|
java_system_identity_manager
|
Sun Java System Identity Manager 6.0 through 6.0 SP4, 7.0, and 7.1 allows remote attackers to inject frames from arbitrary web sites and conduct phishing attacks via unspecified vectors, related to "…
|
NVD-CWE-Other
|
CVE-2008-5118
|
2017-08-8 10:33 |
2008-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260725
|
- |
|
scripts4profit
|
dxshopcart
|
Cross-site scripting (XSS) vulnerability in search.php in Scripts4Profit DXShopCart 4.30mc allows remote attackers to inject arbitrary web script or HTML via the keyword parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2008-5119
|
2017-08-8 10:33 |
2008-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260726
|
- |
|
ektron
|
cms4000.net
|
SQL injection vulnerability in WorkArea/ContentRatingGraph.aspx in Ektron CMS400.NET 7.5.2 and earlier allows remote attackers to execute arbitrary SQL commands via the res parameter.
|
CWE-89
SQL Injection
|
CVE-2008-5122
|
2017-08-8 10:33 |
2008-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260727
|
- |
|
boutikone
|
boutikone_cms
|
Cross-site scripting (XSS) vulnerability in search.php in BoutikOne CMS allows remote attackers to inject arbitrary web script or HTML via the search_query parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2008-5126
|
2017-08-8 10:33 |
2008-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260728
|
- |
|
ocean12_technologies
|
membership_manager_pro
|
Ocean12 Membership Manager Pro stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-5128
|
2017-08-8 10:33 |
2008-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260729
|
- |
|
ocean12_technologies
|
poll_manager
|
Ocean12 Poll Manager Pro 1.00 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to o…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-5129
|
2017-08-8 10:33 |
2008-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260730
|
- |
|
ocean12_technologies
|
calendar_manager
|
Ocean12 Calendar Manager Gold 2.04 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-5130
|
2017-08-8 10:33 |
2008-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|