260981
|
- |
|
drupal
|
drupal upload_module
|
The Upload module in Drupal 6.x before 6.4 allows remote authenticated users to edit nodes, delete files, and download unauthorized attachments via unspecified vectors.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-3745
|
2017-08-8 10:32 |
2008-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260982
|
- |
|
webdav
|
neon
|
neon 0.28.0 through 0.28.2 allows remote servers to cause a denial of service (NULL pointer dereference and crash) via vectors related to Digest authentication, Digest domain parameter support, and t…
|
NVD-CWE-Other
|
CVE-2008-3746
|
2017-08-8 10:32 |
2008-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260983
|
- |
|
webdav
|
neon
|
Per: http://cwe.mitre.org/data/definitions/476.html
'CWE-476: NULL Pointer Dereference'
|
NVD-CWE-Other
|
CVE-2008-3746
|
2017-08-8 10:32 |
2008-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260984
|
- |
|
wordpress
|
wordpress
|
The (1) get_edit_post_link and (2) get_edit_comment_link functions in wp-includes/link-template.php in WordPress before 2.6.1 do not force SSL communication in the intended situations, which might al…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-3747
|
2017-08-8 10:32 |
2008-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260985
|
- |
|
yourfreeworld
|
ad-exchange_script
|
SQL injection vulnerability in tr.php in YourFreeWorld Ad-Exchange Script allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2008-3752
|
2017-08-8 10:32 |
2008-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260986
|
- |
|
yourfreeworld
|
programs_rating_script
|
SQL injection vulnerability in details.php in YourFreeWorld Programs Rating Script allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2008-3753
|
2017-08-8 10:32 |
2008-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260987
|
- |
|
lussumo
|
vanilla
|
Cross-site request forgery (CSRF) vulnerability in ajax/UpdateCheck.php in Vanilla 1.1.4 and earlier has unknown impact and remote attack vectors.
|
NVD-CWE-noinfo CWE-352
Origin Validation Error
|
CVE-2008-3759
|
2017-08-8 10:32 |
2008-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260988
|
- |
|
lussumo
|
vanilla
|
Cross-site request forgery (CSRF) vulnerability in the sign-out page in Vanilla 1.1.4 and earlier allows remote attackers to hijack the authentication of arbitrary users for requests that trigger a l…
|
CWE-352
Origin Validation Error
|
CVE-2008-3760
|
2017-08-8 10:32 |
2008-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260989
|
- |
|
realtime_internet_band_rehearsal
|
low_latency_internet_connection_tool
|
Realtime Internet Band Rehearsal Low-Latency (Internet) Connection tool (llcon) before 2.1.2 allows remote attackers to cause a denial of service (application crash) via malformed protocol messages.
|
CWE-20
Improper Input Validation
|
CVE-2008-3766
|
2017-08-8 10:32 |
2008-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260990
|
- |
|
vbulletin
|
vbulletin
|
Cross-site scripting (XSS) vulnerability in vBulletin 3.7.2 PL1 and 3.6.10 PL3, when "Show New Private Message Notification Pop-Up" is enabled, allows remote authenticated users to inject arbitrary w…
|
CWE-79
Cross-site Scripting
|
CVE-2008-3773
|
2017-08-8 10:32 |
2008-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|