261111
|
- |
|
componentone
|
vsflexgrid
|
Stack-based buffer overflow in the VSFlexGrid.VSFlexGridL ActiveX control in ComponentOne VSFlexGrid 7.0.1.151 and 8.0.20072.239 allows remote attackers to execute arbitrary code via a long first arg…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2008-4132
|
2017-08-8 10:32 |
2008-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261112
|
- |
|
razorecommerce
|
shopping_cart
|
SQL injection vulnerability in category_search.php in RazorCommerce Shopping Cart allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2008-4143
|
2017-08-8 10:32 |
2008-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261113
|
- |
|
drupal
|
mailsave
|
Cross-site scripting (XSS) vulnerability in the Mailsave module 5.x before 5.x-3.3 and 6.x before 6.x-1.3, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via an e…
|
CWE-79
Cross-site Scripting
|
CVE-2008-4147
|
2017-08-8 10:32 |
2008-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261114
|
- |
|
drupal
|
mailhandler
|
SQL injection vulnerability in the Mailhandler module 5.x before 5.x-1.4 and 6.x before 6.x-1.4, a module for Drupal, allows remote attackers to execute arbitrary SQL commands via unspecified vectors…
|
CWE-89
SQL Injection
|
CVE-2008-4148
|
2017-08-8 10:32 |
2008-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261115
|
- |
|
drupal
|
link_to_us
|
Cross-site scripting (XSS) vulnerability in the Greg Holsclaw Link to Us module 5.x before 5.x-1.1 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via the "Link pa…
|
CWE-79
Cross-site Scripting
|
CVE-2008-4149
|
2017-08-8 10:32 |
2008-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261116
|
- |
|
drupal
|
talk
|
Cross-site scripting (XSS) vulnerability in the Talk module 5.x before 5.x-1.3 and 6.x before 6.x-1.5, a module for Drupal, allows remote authenticated users to inject arbitrary web script or HTML vi…
|
CWE-79
Cross-site Scripting
|
CVE-2008-4152
|
2017-08-8 10:32 |
2008-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261117
|
- |
|
drupal
|
talk
|
The Talk module 5.x before 5.x-1.3 and 6.x before 6.x-1.5, a module for Drupal, does not perform access checks for a node before displaying comments, which allows remote attackers to obtain sensitive…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-4153
|
2017-08-8 10:32 |
2008-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261118
|
- |
|
isc
|
bind
|
Unspecified vulnerability in ISC BIND 9.3.5-P2-W1, 9.4.2-P2-W1, and 9.5.0-P2-W1 on Windows allows remote attackers to cause a denial of service (UDP client handler termination) via unknown vectors.
|
NVD-CWE-noinfo CWE-20
Improper Input Validation
|
CVE-2008-4163
|
2017-08-8 10:32 |
2008-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261119
|
- |
|
kolab
|
kolab_groupware_server
|
admin/user/create_user.php in Kolab Groupware Server 1.0.0 places a user password in an HTTP GET request, which allows local administrators, and possibly remote attackers, to obtain cleartext passwor…
|
CWE-310
Cryptographic Issues
|
CVE-2008-4165
|
2017-08-8 10:32 |
2008-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261120
|
- |
|
rfaah
|
cars-vehicles_script
|
SQL injection vulnerability in page.php in Cars & Vehicle (aka Cars-Vehicle Script) allows remote attackers to execute arbitrary SQL commands via the lnkid parameter.
|
CWE-89
SQL Injection
|
CVE-2008-4172
|
2017-08-8 10:32 |
2008-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|