262861
|
- |
|
clansphere
|
clansphere
|
Multiple unspecified vulnerabilities in ClanSphere before 2008.2.1 allow remote attackers to obtain sensitive information, and possibly have unknown other impact, via vectors related to "javascript i…
|
NVD-CWE-noinfo
|
CVE-2008-6470
|
2017-08-17 10:29 |
2009-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262862
|
- |
|
dotnetblogengine
|
blogengine.net
|
Cross-site scripting (XSS) vulnerability in blog/search.aspx in BlogEngine.NET allows remote attackers to inject arbitrary web script or HTML via the q parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2008-6476
|
2017-08-17 10:29 |
2009-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262863
|
- |
|
denis_moinel
|
phpgkit
|
PHP remote file inclusion vulnerability in connexion.php in PHPGKit 0.9 allows remote attackers to execute arbitrary PHP code via a URL in the DOCUMENT_ROOT parameter. NOTE: the provenance of this i…
|
CWE-94
Code Injection
|
CVE-2008-6491
|
2017-08-17 10:29 |
2009-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262864
|
- |
|
codetoad
|
asp_shopping_cart_script
|
Cross-site scripting (XSS) vulnerability in CodeToad ASP Shopping Cart Script allows remote attackers to inject arbitrary web script or HTML via the query string to the default URI.
|
CWE-79
Cross-site Scripting
|
CVE-2008-6500
|
2017-08-17 10:29 |
2009-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262865
|
- |
|
opensymphony apache
|
xwork struts
|
ParametersInterceptor in OpenSymphony XWork 2.0.x before 2.0.6 and 2.1.x before 2.1.2, as used in Apache Struts and other products, does not properly restrict # (pound sign) references to context obj…
|
CWE-20
Improper Input Validation
|
CVE-2008-6504
|
2017-08-17 10:29 |
2009-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262866
|
- |
|
phpbb
|
phpbb
|
Unspecified vulnerability in phpBB before 3.0.4 allows attackers to bypass intended access restrictions and activate de-activated accounts via unknown vectors.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-6506
|
2017-08-17 10:29 |
2009-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262867
|
- |
|
google
|
gears
|
Cross-domain vulnerability in the WorkerPool API in Google Gears before 0.5.4.2 allows remote attackers to bypass the Same Origin Policy and the intended access restrictions of the allowCrossOrigin f…
|
NVD-CWE-Other
|
CVE-2008-6512
|
2017-08-17 10:29 |
2009-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262868
|
- |
|
vclcomponents
|
yappa-ng
|
Cross-site scripting (XSS) vulnerability in Fritz Berger yet another php photo album - next generation (yappa-ng) allows remote attackers to inject arbitrary web script or HTML via the query string t…
|
CWE-79
Cross-site Scripting
|
CVE-2008-6515
|
2017-08-17 10:29 |
2009-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262869
|
- |
|
phpkf
|
phpkf-portal
|
Multiple directory traversal vulnerabilities in phpKF-Portal 1.10 allow remote attackers to include arbitrary files via a .. (dot dot) in the (1) tema_dizin parameter to baslik.php and (2) portal_aya…
|
CWE-22
Path Traversal
|
CVE-2008-6516
|
2017-08-17 10:29 |
2009-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262870
|
- |
|
imatix
|
xitami
|
Multiple format string vulnerabilities in the SSI filter in Xitami Web Server 2.5c2, and possibly other versions, allow remote attackers to cause a denial of service (daemon crash) and possibly execu…
|
CWE-134
Use of Externally-Controlled Format String
|
CVE-2008-6520
|
2017-08-17 10:29 |
2009-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|