257741
|
- |
|
sun
|
opensolaris solaris
|
The kernel in Sun Solaris 8 through 10 and OpenSolaris before snv_90 allows local users to bypass chroot, zones, and the Solaris Trusted Extensions multi-level security policy, and establish a covert…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-3875
|
2017-09-29 10:31 |
2008-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257742
|
- |
|
acoustica
|
mixcraft
|
Stack-based buffer overflow in Acoustica Mixcraft 4.1 Build 96 and 4.2 Build 98 allows user-assisted attackers to execute arbitrary code via a crafted .mx4 file. NOTE: it was later reported that ver…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2008-3877
|
2017-09-29 10:31 |
2008-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257743
|
- |
|
hans_oesterholt
|
cmme
|
Multiple cross-site scripting (XSS) vulnerabilities in statistics.php in Content Management Made Easy (CMME) 1.12 allow remote attackers to inject arbitrary web script or HTML via the (1) page and (2…
|
CWE-79
Cross-site Scripting
|
CVE-2008-3923
|
2017-09-29 10:31 |
2008-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257744
|
- |
|
hans_oesterholt
|
cmme
|
The "Make a backup" functionality in Content Management Made Easy (CMME) 1.12 stores sensitive information under the web root with insufficient access control, which allows remote attackers to discov…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-3924
|
2017-09-29 10:31 |
2008-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257745
|
- |
|
hans_oesterholt
|
cmme
|
Cross-site request forgery (CSRF) vulnerability in admin.php in Content Management Made Easy (CMME) 1.12 allows remote attackers to trigger the logout of an administrative user via a logout action.
|
CWE-352
Origin Validation Error
|
CVE-2008-3925
|
2017-09-29 10:31 |
2008-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257746
|
- |
|
hans_oesterholt
|
cmme
|
Multiple directory traversal vulnerabilities in Content Management Made Easy (CMME) 1.12 allow remote attackers to (1) read arbitrary files via a .. (dot dot) in the env parameter in a weblog action …
|
CWE-22
Path Traversal
|
CVE-2008-3926
|
2017-09-29 10:31 |
2008-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257747
|
- |
|
ezonescripts
|
living_local
|
SQL injection vulnerability in listtest.php in eZoneScripts Living Local 1.1 allows remote attackers to execute arbitrary SQL commands via the r parameter.
|
CWE-89
SQL Injection
|
CVE-2008-3943
|
2017-09-29 10:31 |
2008-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257748
|
- |
|
discountedscripts
|
acg_ptp
|
SQL injection vulnerability in index.php in ACG-PTP 1.0.6 allows remote attackers to execute arbitrary SQL commands via the adid parameter in an adorder action.
|
CWE-89
SQL Injection
|
CVE-2008-3944
|
2017-09-29 10:31 |
2008-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257749
|
- |
|
source_workshop
|
words_tag_script
|
SQL injection vulnerability in index.php in Words tag 1.2 allows remote attackers to execute arbitrary SQL commands via the word parameter in a claim action.
|
CWE-89
SQL Injection
|
CVE-2008-3945
|
2017-09-29 10:31 |
2008-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257750
|
- |
|
vastal
|
agent_zone
|
SQL injection vulnerability in view_ann.php in Vastal I-Tech Agent Zone (aka The Real Estate Script) allows remote attackers to execute arbitrary SQL commands via the ann_id parameter.
|
CWE-89
SQL Injection
|
CVE-2008-3951
|
2017-09-29 10:31 |
2008-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|