261431
|
- |
|
myer_sound_laboratories
|
muscle
|
Stack-based buffer overflow in the Message::AddToString function in message/Message.cpp in MUSCLE before 4.40 allows remote attackers to cause a denial of service (crash) and possibly execute arbitra…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2008-4631
|
2017-08-8 10:32 |
2008-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261432
|
- |
|
drupal
|
node_clone
|
SQL injection vulnerability in Node Vote 5.x before 5.x-1.1 and 6.x before 6.x-1.0, a module for Drupal, when "Allow user to vote again" is enabled, allows remote authenticated users to execute arbit…
|
CWE-89
SQL Injection
|
CVE-2008-4633
|
2017-08-8 10:32 |
2008-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261433
|
- |
|
six_apart
|
movable_type
|
Cross-site scripting (XSS) vulnerability in Movable Type 4 through 4.21 allows remote attackers to inject arbitrary web script or HTML via unknown vectors related to the administrative page, a differ…
|
CWE-79
Cross-site Scripting
|
CVE-2008-4634
|
2017-08-8 10:32 |
2008-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261434
|
- |
|
hisanaga_electric_co
|
hisa_cart
|
Unspecified vulnerability in Hisanaga Electric Co, Ltd. hisa_cart 1.29 and earlier, a module for XOOPS, allows remote attackers to obtain sensitive user information via unknown vectors.
|
CWE-200
Information Exposure
|
CVE-2008-4635
|
2017-08-8 10:32 |
2008-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261435
|
- |
|
cpcommerce
|
cpcommerce
|
Cross-site scripting (XSS) vulnerability in cpCommerce before 1.2.4 allows remote attackers to inject arbitrary web script or HTML via unknown vectors in the advanced search feature. NOTE: this is p…
|
CWE-79
Cross-site Scripting
|
CVE-2008-4637
|
2017-08-8 10:32 |
2008-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261436
|
- |
|
cpcommerce
|
cpcommerce
|
Patch Information: http://cpcommerce.cpradio.org/downloads.php
|
CWE-79
Cross-site Scripting
|
CVE-2008-4637
|
2017-08-8 10:32 |
2008-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261437
|
- |
|
sweetcms
|
sweetcms
|
SQL injection vulnerability in index.php in sweetCMS 1.5.2 allows remote attackers to execute arbitrary SQL commands via the page parameter.
|
CWE-89
SQL Injection
|
CVE-2008-4647
|
2017-08-8 10:32 |
2008-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261438
|
- |
|
elxis
|
elxis_cms
|
Cross-site scripting (XSS) vulnerability in index.php in Elxis CMS 2008.1 revision 2204 allows remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO or the (2) option, (3) Ite…
|
CWE-79
Cross-site Scripting
|
CVE-2008-4648
|
2017-08-8 10:32 |
2008-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261439
|
- |
|
elxis
|
elxis_cms
|
Session fixation vulnerability in Elxis CMS 2008.1 revision 2204 allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.
|
CWE-287
Improper Authentication
|
CVE-2008-4649
|
2017-08-8 10:32 |
2008-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261440
|
- |
|
jetbox
|
jetbox_cms
|
Multiple SQL injection vulnerabilities in Jetbox CMS 2.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) orderby parameter to admin/cms/images.php and the (2) nav_id pa…
|
CWE-89
SQL Injection
|
CVE-2008-4651
|
2017-08-8 10:32 |
2008-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|