261301
|
- |
|
phpbb
|
phpbb
|
The search function in phpBB 2.x provides a search_id value that leaks the state of PHP's PRNG, which allows remote attackers to obtain potentially sensitive information, as demonstrated by a cross-a…
|
NVD-CWE-noinfo CWE-200
Information Exposure
|
CVE-2008-4125
|
2017-08-8 10:32 |
2008-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261302
|
- |
|
gallery
|
gallery
|
Gallery before 1.5.9, and 2.x before 2.2.6, does not properly handle ZIP archives containing symbolic links, which allows remote authenticated users to conduct directory traversal attacks and read ar…
|
CWE-22
Path Traversal
|
CVE-2008-4129
|
2017-08-8 10:32 |
2008-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261303
|
- |
|
gallery
|
gallery
|
Cross-site scripting (XSS) vulnerability in Gallery 2.x before 2.2.6 allows remote attackers to inject arbitrary web script or HTML via a crafted Flash animation, related to the ability of the animat…
|
CWE-79
Cross-site Scripting
|
CVE-2008-4130
|
2017-08-8 10:32 |
2008-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261304
|
- |
|
componentone
|
vsflexgrid
|
Stack-based buffer overflow in the VSFlexGrid.VSFlexGridL ActiveX control in ComponentOne VSFlexGrid 7.0.1.151 and 8.0.20072.239 allows remote attackers to execute arbitrary code via a long first arg…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2008-4132
|
2017-08-8 10:32 |
2008-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261305
|
- |
|
razorecommerce
|
shopping_cart
|
SQL injection vulnerability in category_search.php in RazorCommerce Shopping Cart allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2008-4143
|
2017-08-8 10:32 |
2008-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261306
|
- |
|
drupal
|
mailsave
|
Cross-site scripting (XSS) vulnerability in the Mailsave module 5.x before 5.x-3.3 and 6.x before 6.x-1.3, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via an e…
|
CWE-79
Cross-site Scripting
|
CVE-2008-4147
|
2017-08-8 10:32 |
2008-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261307
|
- |
|
drupal
|
mailhandler
|
SQL injection vulnerability in the Mailhandler module 5.x before 5.x-1.4 and 6.x before 6.x-1.4, a module for Drupal, allows remote attackers to execute arbitrary SQL commands via unspecified vectors…
|
CWE-89
SQL Injection
|
CVE-2008-4148
|
2017-08-8 10:32 |
2008-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261308
|
- |
|
drupal
|
link_to_us
|
Cross-site scripting (XSS) vulnerability in the Greg Holsclaw Link to Us module 5.x before 5.x-1.1 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via the "Link pa…
|
CWE-79
Cross-site Scripting
|
CVE-2008-4149
|
2017-08-8 10:32 |
2008-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261309
|
- |
|
drupal
|
talk
|
Cross-site scripting (XSS) vulnerability in the Talk module 5.x before 5.x-1.3 and 6.x before 6.x-1.5, a module for Drupal, allows remote authenticated users to inject arbitrary web script or HTML vi…
|
CWE-79
Cross-site Scripting
|
CVE-2008-4152
|
2017-08-8 10:32 |
2008-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261310
|
- |
|
drupal
|
talk
|
The Talk module 5.x before 5.x-1.3 and 6.x before 6.x-1.5, a module for Drupal, does not perform access checks for a node before displaying comments, which allows remote attackers to obtain sensitive…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-4153
|
2017-08-8 10:32 |
2008-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|