260791
|
- |
|
rsyslog
|
rsyslog
|
The ACL handling in rsyslog 3.12.1 to 3.20.0, 4.1.0, and 4.1.1 does not follow $AllowedSender directive, which allows remote attackers to bypass intended access restrictions and spoof log messages or…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-5617
|
2017-08-8 10:33 |
2008-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260792
|
- |
|
roundcube
|
webmail
|
RoundCube Webmail (roundcubemail) before 0.2-beta allows remote attackers to cause a denial of service (memory consumption) via crafted size parameters that are used to create a large quota image.
|
CWE-399
Resource Management Errors
|
CVE-2008-5620
|
2017-08-8 10:33 |
2008-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260793
|
- |
|
typo3
|
typo3
|
Cross-site scripting (XSS) vulnerability in the file backend module in TYPO3 4.2.2 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2008-5644
|
2017-08-8 10:33 |
2008-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260794
|
- |
|
orb_networks
|
orb
|
Directory traversal vulnerability in the media server in Orb Networks Orb before 2.01.0022 allows remote attackers to read arbitrary files via directory traversal sequences in an HTTP GET request.
|
CWE-22
Path Traversal
|
CVE-2008-5645
|
2017-08-8 10:33 |
2008-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260795
|
- |
|
trac
|
trac
|
Unspecified vulnerability in Trac before 0.11.2 allows attackers to cause a denial of service via unknown attack vectors related to "certain wiki markup."
|
NVD-CWE-noinfo
|
CVE-2008-5646
|
2017-08-8 10:33 |
2008-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260796
|
- |
|
trac
|
trac
|
Unspecified vulnerability in the HTML sanitizer filter in Trac before 0.11.2 allows attackers to conduct phishing attacks via unknown attack vectors.
|
NVD-CWE-noinfo
|
CVE-2008-5647
|
2017-08-8 10:33 |
2008-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260797
|
- |
|
myiosoft
|
easybookmarker
|
Multiple SQL injection vulnerabilities in MyioSoft EasyBookMarker 4.0 allow remote attackers to execute arbitrary SQL commands via the (1) delete_folder and (2) delete_link parameters to unspecified …
|
CWE-89
SQL Injection
|
CVE-2008-5655
|
2017-08-8 10:33 |
2008-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260798
|
- |
|
typo3
|
typo3
|
Cross-site scripting (XSS) vulnerability in the frontend plugin for the felogin system extension in TYPO3 4.2.0, 4.2.1 and 4.2.2 allows remote attackers to inject arbitrary web script or HTML via unk…
|
CWE-79
Cross-site Scripting
|
CVE-2008-5656
|
2017-08-8 10:33 |
2008-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260799
|
- |
|
quassel
|
quassel_core
|
CRLF injection vulnerability in Quassel Core before 0.3.0.3 allows remote attackers to spoof IRC messages as other users via a crafted CTCP message.
|
CWE-20
Improper Input Validation
|
CVE-2008-5657
|
2017-08-8 10:33 |
2008-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260800
|
- |
|
gnu
|
classpath
|
The gnu.java.security.util.PRNG class in GNU Classpath 0.97.2 and earlier uses a predictable seed based on the system time, which makes it easier for context-dependent attackers to conduct brute forc…
|
CWE-310
Cryptographic Issues
|
CVE-2008-5659
|
2017-08-8 10:33 |
2008-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|