261211
|
- |
|
adobe
|
flash_player
|
The System.setClipboard method in ActionScript in Adobe Flash Player 9.0.124.0 and earlier allows remote attackers to populate the clipboard with a URL that is difficult to delete and does not requir…
|
NVD-CWE-Other
|
CVE-2008-3873
|
2017-08-8 10:32 |
2008-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261212
|
- |
|
caudium
|
caudium
|
configvar in Caudium 1.4.12 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/roken#####.pike temporary file.
|
CWE-59
Link Following
|
CVE-2008-3883
|
2017-08-8 10:32 |
2008-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261213
|
- |
|
blogn
|
blogn
|
Cross-site scripting (XSS) vulnerability in Blogn (BURO GUN) 1.9.7 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different issue than CVE-2006-…
|
CWE-79
Cross-site Scripting
|
CVE-2008-3884
|
2017-08-8 10:32 |
2008-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261214
|
- |
|
blogn
|
blogn
|
Cross-site request forgery (CSRF) vulnerability in Blogn (BURO GUN) 1.9.7 and earlier allows remote attackers to hijack the authentication of arbitrary users for requests that make content modificati…
|
CWE-352
Origin Validation Error
|
CVE-2008-3885
|
2017-08-8 10:32 |
2008-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261215
|
- |
|
dotproject
|
dotproject
|
Multiple cross-site scripting (XSS) vulnerabilities in index.php in dotProject 2.1.2 allow remote attackers to inject arbitrary web script or HTML via (1) the inactive parameter in a tasks action, (2…
|
CWE-79
Cross-site Scripting
|
CVE-2008-3886
|
2017-08-8 10:32 |
2008-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261216
|
- |
|
dotproject
|
dotproject
|
Multiple SQL injection vulnerabilities in index.php in dotProject 2.1.2 allow (1) remote authenticated users to execute arbitrary SQL commands via the tab parameter in a projects action, and (2) remo…
|
CWE-89
SQL Injection
|
CVE-2008-3887
|
2017-08-8 10:32 |
2008-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261217
|
- |
|
dotproject
|
dotproject
|
http://secunia.com/advisories/31681:
"Successful exploitation of this vulnerability allows e.g. retrieval of administrator usernames and password hashes, but requires valid user credentials."
…
|
CWE-89
SQL Injection
|
CVE-2008-3887
|
2017-08-8 10:32 |
2008-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261218
|
- |
|
freebsd
|
freebsd
|
The kernel in FreeBSD 6.3 through 7.0 on amd64 platforms can make an extra swapgs call after a General Protection Fault (GPF), which allows local users to gain privileges by triggering a GPF during t…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-3890
|
2017-08-8 10:32 |
2008-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261219
|
- |
|
asterisk trixbox
|
p_b_x pbx
|
Asterisk Open Source 1.2.x before 1.2.32, 1.4.x before 1.4.24.1, and 1.6.0.x before 1.6.0.8; Asterisk Business Edition A.x.x, B.x.x before B.2.5.8, C.1.x.x before C.1.10.5, and C.2.x.x before C.2.3.3…
|
CWE-200
Information Exposure
|
CVE-2008-3903
|
2017-08-8 10:32 |
2008-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261220
|
- |
|
asterisk trixbox
|
p_b_x pbx
|
Additional details can be found here: http://www.voipsa.org/pipermail/voipsec_voipsa.org/2006-May/001628.html
|
CWE-200
Information Exposure
|
CVE-2008-3903
|
2017-08-8 10:32 |
2008-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|