257581
|
- |
|
mielke
|
brltty
|
Untrusted search path vulnerability in libbrlttybba.so in brltty 3.7.2 allows local users to gain privileges via a crafted library, related to an incorrect RPATH setting.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-3279
|
2017-09-29 10:31 |
2010-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257582
|
- |
|
mielke
|
brltty
|
Per: http://cwe.mitre.org/data/definitions/426.html
'CWE-426: Untrusted Search Path'
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-3279
|
2017-09-29 10:31 |
2010-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257583
|
- |
|
fedora redhat
|
directory_server
|
Multiple memory leaks in Red Hat Directory Server 7.1 before SP7, Red Hat Directory Server 8, and Fedora Directory Server 1.1.1 and earlier allow remote attackers to cause a denial of service (memory…
|
CWE-399
Resource Management Errors
|
CVE-2008-3283
|
2017-09-29 10:31 |
2008-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257584
|
- |
|
aprox
|
aprox_cms_engine aproxengine
|
SQL injection vulnerability in index.php in AproxEngine (aka Aprox CMS Engine) 5.1.0.4 allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2008-3291
|
2017-09-29 10:31 |
2008-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257585
|
- |
|
ezwebalbum
|
ezwebalbum
|
constants.inc in EZWebAlbum 1.0 allows remote attackers to bypass authentication and gain administrator privileges by setting the photoalbumadmin cookie, as demonstrated via addpage.php.
|
CWE-287
Improper Authentication
|
CVE-2008-3292
|
2017-09-29 10:31 |
2008-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257586
|
- |
|
tuxplanet
|
bilboblog
|
SQL injection vulnerability in admin/delete.php in BilboBlog 0.2.1, when magic_quotes_gpc is disabled, allows remote authenticated administrators to execute arbitrary SQL commands via the num paramet…
|
CWE-89
SQL Injection
|
CVE-2008-3302
|
2017-09-29 10:31 |
2008-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257587
|
- |
|
tuxplanet
|
bilboblog
|
admin/login.php in BilboBlog 0.2.1, when register_globals is enabled, allows remote attackers to bypass authentication and obtain administrative access via a direct request that sets the login, admin…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-3303
|
2017-09-29 10:31 |
2008-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257588
|
- |
|
carlos_desseno
|
youtube_blog
|
Cross-site scripting (XSS) vulnerability in mensaje.php in C. Desseno YouTube Blog (ytb) 0.1 allows remote attackers to inject arbitrary web script or HTML via the m parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2008-3305
|
2017-09-29 10:31 |
2008-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257589
|
- |
|
youtube_blog
|
youtube_blog
|
SQL injection vulnerability in todos.php in C. Desseno YouTube Blog (ytb) 0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2008-3306.
|
CWE-89
SQL Injection
|
CVE-2008-3307
|
2017-09-29 10:31 |
2008-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257590
|
- |
|
carlos_desseno
|
youtube_blog
|
PHP remote file inclusion vulnerability in cuenta/cuerpo.php in C. Desseno YouTube Blog (ytb) 0.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in…
|
CWE-94
Code Injection
|
CVE-2008-3308
|
2017-09-29 10:31 |
2008-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|