257281
|
- |
|
meltingicefs
|
meltingice_file_system
|
MeltingIce File System 1.0 allows remote attackers to bypass application authentication, create new user accounts, and exceed application quotas via a direct request to admin/adduser.php.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-2348
|
2017-09-29 10:31 |
2008-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257282
|
- |
|
zomp
|
zomplog
|
Zomplog 3.8.2 and earlier allows remote attackers to gain administrative access by creating an admin account via a direct request to install/newuser.php with the admin parameter set to 1.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-2349
|
2017-09-29 10:31 |
2008-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257283
|
- |
|
webmanager-pro
|
cms_webmanager-pro
|
Multiple SQL injection vulnerabilities in index.php in CMS WebManager-Pro allow remote attackers to execute arbitrary SQL commands via the (1) lang_id and (2) menu_id parameters.
|
CWE-89
SQL Injection
|
CVE-2008-2351
|
2017-09-29 10:31 |
2008-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257284
|
- |
|
gnugallery
|
gnugallery
|
Directory traversal vulnerability in admin.php in GNU/Gallery 1.1.1.0 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the show parameter.
|
CWE-22
Path Traversal
|
CVE-2008-2353
|
2017-09-29 10:31 |
2008-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257285
|
- |
|
wr-script
|
wr-meeting
|
Directory traversal vulnerability in index.php in WR-Meeting 1.0, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the msn…
|
CWE-22
Path Traversal
|
CVE-2008-2355
|
2017-09-29 10:31 |
2008-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257286
|
- |
|
archangelmgt
|
archangel_weblog
|
SQL injection vulnerability in index.php in Archangel Weblog 0.90.02 and earlier allows remote attackers to execute arbitrary SQL commands via the post_id parameter.
|
CWE-89
SQL Injection
|
CVE-2008-2356
|
2017-09-29 10:31 |
2008-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257287
|
- |
|
linux
|
linux_kernel
|
Integer overflow in the dccp_feat_change function in net/dccp/feat.c in the Datagram Congestion Control Protocol (DCCP) subsystem in the Linux kernel 2.6.18, and 2.6.17 through 2.6.20, allows local u…
|
CWE-189
Numeric Errors
|
CVE-2008-2358
|
2017-09-29 10:31 |
2008-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257288
|
- |
|
linux
|
linux_kernel
|
Patch information can be found at the following location:
http://lists.debian.org/debian-security-announce/2008/msg00172.html
|
CWE-189
Numeric Errors
|
CVE-2008-2358
|
2017-09-29 10:31 |
2008-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257289
|
- |
|
openoffice
|
openoffice
|
Untrusted search path vulnerability in a certain Red Hat build script for OpenOffice.org (OOo) 1.1.x on Red Hat Enterprise Linux (RHEL) 3 and 4 allows local users to gain privileges via a malicious l…
|
CWE-16
Configuration
|
CVE-2008-2366
|
2017-09-29 10:31 |
2008-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257290
|
- |
|
squirrelmail
|
squirrelmail
|
Cross-site scripting (XSS) vulnerability in SquirrelMail before 1.4.17 allows remote attackers to inject arbitrary web script or HTML via a crafted hyperlink in an HTML part of an e-mail message.
|
CWE-79
Cross-site Scripting
|
CVE-2008-2379
|
2017-09-29 10:31 |
2008-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|