261331
|
- |
|
aguestbook
|
an_guestbook
|
Cross-site scripting (XSS) vulnerability in send_email.php in AN Guestbook (ANG) 0.4 allows remote attackers to inject arbitrary web script or HTML via the postid parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2008-2414
|
2017-08-8 10:31 |
2008-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261332
|
- |
|
digitalhive
|
digitalhive
|
Directory traversal vulnerability in template/purpletech/base_include.php in DigitalHive (aka hive) 2.0 RC2 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in …
|
CWE-22
Path Traversal
|
CVE-2008-2415
|
2017-08-8 10:31 |
2008-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261333
|
- |
|
mozilla
|
firefox
|
Mozilla Firefox 2.0.0.14 allows remote attackers to cause a denial of service (heap corruption and application crash) or possibly execute arbitrary code by triggering an error condition during certai…
|
CWE-399
Resource Management Errors
|
CVE-2008-2419
|
2017-08-8 10:31 |
2008-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261334
|
- |
|
stunnel
|
stunnel
|
The OCSP functionality in stunnel before 4.24 does not properly search certificate revocation lists (CRL), which allows remote attackers to bypass intended access restrictions by using revoked certif…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-2420
|
2017-08-8 10:31 |
2008-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261335
|
- |
|
webslider
|
webslider
|
SQL injection vulnerability in index.php in Web Slider 0.6 allows remote attackers to execute arbitrary SQL commands via the slide parameter in a slides action. NOTE: the provenance of this informat…
|
CWE-89
SQL Injection
|
CVE-2008-2422
|
2017-08-8 10:31 |
2008-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261336
|
- |
|
interchange_development_group
|
interchange
|
Unspecified vulnerability in Interchange before 5.6.0 and before 5.5.2 allows remote attackers to cause a denial of service via crafted HTTP requests. NOTE: this might overlap CVE-2007-2635.
|
NVD-CWE-noinfo
|
CVE-2008-2423
|
2017-08-8 10:31 |
2008-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261337
|
- |
|
icdevgroup
|
interchange
|
Unspecified vulnerability in the 404 error page for the "Standard demo" in Interchange before 5.6.0 and before 5.5.2 has unknown impact and attack vectors.
|
NVD-CWE-noinfo
|
CVE-2008-2424
|
2017-08-8 10:31 |
2008-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261338
|
- |
|
fichive
|
fichive
|
SQL injection vulnerability in index.php in FicHive 1.0 allows remote attackers to execute arbitrary SQL commands via the letter parameter in a Search action, a different vector than CVE-2008-2416. …
|
CWE-89
SQL Injection
|
CVE-2008-2425
|
2017-08-8 10:31 |
2008-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261339
|
- |
|
novell
|
iprint
|
Multiple buffer overflows in Novell iPrint Client before 5.06 allow remote attackers to execute arbitrary code by calling the Novell iPrint ActiveX control (aka ienipp.ocx) with (1) a long third argu…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2008-2431
|
2017-08-8 10:31 |
2008-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261340
|
- |
|
ikemcg
|
phpinstantgallery
|
Multiple cross-site scripting (XSS) vulnerabilities in Isaac McGowan phpInstantGallery 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) gallery parameter to (a) index.php…
|
CWE-79
Cross-site Scripting
|
CVE-2008-2449
|
2017-08-8 10:31 |
2008-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|