276081
|
- |
|
freshmeat
|
xwine
|
w_editeur.c in XWine 1.0.1 for Debian GNU/Linux allows local users to overwrite or print arbitrary files via a symlink attack on the temporaire temporary file. NOTE: some of these details are obtain…
|
CWE-59
Link Following
|
CVE-2008-0930
|
2008-09-6 06:36 |
2008-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276082
|
- |
|
xwine
|
xwine
|
w_export.c in XWine 1.0.1 on Debian GNU/Linux sets insecure permissions (0666) for /etc/wine/config, which might allow local users to execute arbitrary commands or cause a denial of service by modify…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-0931
|
2008-09-6 06:36 |
2008-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276083
|
- |
|
xoops
|
prayer_list_module
|
SQL injection vulnerability in index.php in the Prayer List (prayerlist) 1.04 module for XOOPS allows remote attackers to execute arbitrary SQL commands via the cid parameter in a view action.
|
CWE-89
SQL Injection
|
CVE-2008-0936
|
2008-09-6 06:36 |
2008-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276084
|
- |
|
tinyevent xoops
|
tinyevent tiny_event_module
|
SQL injection vulnerability in index.php in the Tiny Event (tinyevent) 1.01 module for XOOPS allows remote attackers to execute arbitrary SQL commands via the id parameter in a print action, a differ…
|
CWE-89
SQL Injection
|
CVE-2008-0937
|
2008-09-6 06:36 |
2008-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276085
|
- |
|
webgui
|
webgui
|
Cross-site scripting (XSS) vulnerability in Plain Black WebGUI before 7.4.24 allows remote attackers to inject arbitrary web script or HTML when creating a username, a different vulnerability than CV…
|
CWE-79
Cross-site Scripting
|
CVE-2008-0940
|
2008-09-6 06:36 |
2008-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276086
|
- |
|
matts_whois
|
matts_whois
|
Cross-site scripting (XSS) vulnerability in mwhois.php in Matt Wilson Matt's Whois (MWhois) allows remote attackers to inject arbitrary web script or HTML via the domain parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2008-1041
|
2008-09-6 06:36 |
2008-02-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276087
|
- |
|
intervideo
|
windvd_media_center
|
InterVideo IMC Server (aka IMCSvr.exe) and InterVideo Home Theater (aka IHT.exe) in InterVideo WinDVD Media Center 2.11.15.0 allow remote attackers to cause a denial of service (NULL dereference and …
|
CWE-20
Improper Input Validation
|
CVE-2008-1062
|
2008-09-6 06:36 |
2008-02-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276088
|
- |
|
xoops
|
xm_memberstats
|
Multiple SQL injection vulnerabilities in index.php in the XM-Memberstats (xmmemberstats) 2.0e module for XOOPS allow remote attackers to execute arbitrary SQL commands via the (1) letter or (2) sort…
|
CWE-89
SQL Injection
|
CVE-2008-1065
|
2008-09-6 06:36 |
2008-02-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276089
|
- |
|
maianscriptworld
|
maian_cart
|
Cross-site scripting (XSS) vulnerability in index.php in Maian Cart 1.1 allows remote attackers to inject arbitrary web script or HTML via the keywords parameter in a search command. NOTE: the prove…
|
CWE-79
Cross-site Scripting
|
CVE-2008-1075
|
2008-09-6 06:36 |
2008-02-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276090
|
- |
|
vocera_communications
|
vocera_communications_badge
|
Cisco Unified Wireless IP Phone 7921, when using Protected Extensible Authentication Protocol (PEAP), does not validate server certificates, which allows remote wireless access points to steal hashed…
|
CWE-200
Information Exposure
|
CVE-2008-1113
|
2008-09-6 06:36 |
2008-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|