262611
|
- |
|
ibiblio
|
osprey
|
PHP remote file inclusion vulnerability in ListRecords.php in osprey 1.0a4.1 allows remote attackers to execute arbitrary PHP code via a URL in the xml_dir parameter. NOTE: the provenance of this in…
|
CWE-94
Code Injection
|
CVE-2008-6807
|
2017-08-17 10:29 |
2009-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262612
|
- |
|
mole-group
|
lastminute_script
|
Mole Group Lastminute Script 4.0 and earlier stores passwords in cleartext, which allows context-dependent attackers to obtain sensitive information. NOTE: the provenance of this information is unkn…
|
CWE-255
Credentials Management
|
CVE-2008-6817
|
2017-08-17 10:29 |
2009-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262613
|
- |
|
mole-group
|
real_estate_script
|
Mole Group Real Estate Script 1.1 and earlier stores passwords in cleartext, which allows context-dependent attackers to obtain sensitive information. NOTE: the provenance of this information is unk…
|
CWE-255
Credentials Management
|
CVE-2008-6818
|
2017-08-17 10:29 |
2009-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262614
|
- |
|
ibm
|
db2
|
Buffer overflow in the DAS server in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP2 might allow attackers to execute arbitrary code or cause a denial of service (application crash) via uns…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2008-6821
|
2017-08-17 10:29 |
2009-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262615
|
- |
|
citrix
|
web_interface
|
The disconnection feature in Citrix Web Interface 5.0 and 5.0.1 for Java Application Servers does not properly terminate a user's web interface session, which allows attackers with access to the same…
|
NVD-CWE-Other
|
CVE-2008-6830
|
2017-08-17 10:29 |
2009-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262616
|
- |
|
atlassian
|
jira
|
Multiple cross-site scripting (XSS) vulnerabilities in Atlassian JIRA Enterprise Edition 3.13 allow remote attackers to inject arbitrary web script or HTML via the (1) fullname (Full Name) parameter …
|
CWE-79
Cross-site Scripting
|
CVE-2008-6831
|
2017-08-17 10:29 |
2009-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262617
|
- |
|
atlassian
|
jira
|
Cross-site request forgery (CSRF) vulnerability in Atlassian JIRA Enterprise Edition 3.13 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors. NOTE: the p…
|
CWE-352
Origin Validation Error
|
CVE-2008-6832
|
2017-08-17 10:29 |
2009-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262618
|
- |
|
zoph
|
zoph
|
SQL injection vulnerability in Zoph 0.7.2.1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, a different issue than CVE-2008-3258. NOTE: the provenance of this info…
|
CWE-89
SQL Injection
|
CVE-2008-6837
|
2017-08-17 10:29 |
2009-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262619
|
- |
|
zoph
|
zoph
|
Cross-site scripting (XSS) vulnerability in search.php in Zoph 0.7.2.1 allows remote attackers to inject arbitrary web script or HTML via the _off parameter. NOTE: the provenance of this information…
|
CWE-79
Cross-site Scripting
|
CVE-2008-6838
|
2017-08-17 10:29 |
2009-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262620
|
- |
|
tgs-cms
|
tgs_content_management
|
Multiple cross-site scripting (XSS) vulnerabilities in TGS Content Management 0.3.2r2 allow remote attackers to inject arbitrary web script or HTML via the (1) msg and (2) goodmsg parameters to (a) l…
|
CWE-79
Cross-site Scripting
|
CVE-2008-6839
|
2017-08-17 10:29 |
2009-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|