260891
|
- |
|
attachmate
|
reflection_for_secure_it
|
Multiple unspecified vulnerabilities in Attachmate Reflection for Secure IT UNIX Client and Server before 7.0 SP1 have unknown impact and attack vectors, aka "security vulnerabilities found by 3rd pa…
|
NVD-CWE-noinfo
|
CVE-2008-6021
|
2017-08-8 10:33 |
2009-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260892
|
- |
|
sun
|
opensolaris solaris
|
Unspecified vulnerability in the NFSv4 client module in the kernel on Sun Solaris 10 and OpenSolaris before snv_37, when automountd is used, allows user-assisted remote attackers to cause a denial of…
|
CWE-399
Resource Management Errors
|
CVE-2008-6024
|
2017-08-8 10:33 |
2009-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260893
|
- |
|
bluecube
|
bluecube_cms
|
SQL injection vulnerability in tienda.php in BlueCUBE CMS allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2008-6026
|
2017-08-8 10:33 |
2009-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260894
|
- |
|
achievo
|
achievo
|
Cross-site scripting (XSS) vulnerability in dispatch.php in Achievo 1.3.2 allows remote attackers to inject arbitrary web script or HTML via the atkaction parameter. NOTE: the provenance of this inf…
|
CWE-79
Cross-site Scripting
|
CVE-2008-6034
|
2017-08-8 10:33 |
2009-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260895
|
- |
|
achievo
|
achievo
|
Cross-site scripting (XSS) vulnerability in dispatch.php in Achievo 1.3.2-STABLE allows remote attackers to inject arbitrary web script or HTML via the atknodetype parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2008-6035
|
2017-08-8 10:33 |
2009-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260896
|
- |
|
preprojects
|
pre_e-learning_portal
|
PreProjects Pre E-Learning Portal stores db_elearning.mdb under the web root with insufficient access control, which allows remote attackers to obtain passwords via a direct request.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-6052
|
2017-08-8 10:33 |
2009-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260897
|
- |
|
preprojects
|
pre_resume_submitter
|
PreProjects Pre Resume Submitter stores onlineresume.mdb under the web root with insufficient access control, which allows remote attackers to obtain passwords via a direct request.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-6053
|
2017-08-8 10:33 |
2009-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260898
|
- |
|
preprojects.com
|
pre_courier_and_cargo_business
|
PreProjects Pre Courier and Cargo Business stores dbcourior.mdb under the web root with insufficient access control, which allows remote attackers to obtain passwords via a direct request.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-6054
|
2017-08-8 10:33 |
2009-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260899
|
- |
|
webkit
|
webkit
|
xml/XMLHttpRequest.cpp in WebCore in WebKit before r38566 does not properly restrict access from web pages to the (1) Set-Cookie and (2) Set-Cookie2 HTTP response headers, which allows remote attacke…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-6059
|
2017-08-8 10:33 |
2009-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260900
|
- |
|
meet\#web
|
meet\#web
|
Multiple PHP remote file inclusion vulnerabilities in Meet#Web 0.8 allow remote attackers to execute arbitrary PHP code via a URL in the root_path parameter to (1) modules.php, (2) ManagerResource.cl…
|
CWE-94
Code Injection
|
CVE-2008-6066
|
2017-08-8 10:33 |
2009-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|