256631
|
- |
|
czaries
|
czarnews
|
SQL injection vulnerability in cn_users.php in CzarNews 1.20 and earlier allows remote attackers to execute arbitrary SQL commands via a recook cookie.
|
CWE-89
SQL Injection
|
CVE-2008-4203
|
2017-09-29 10:32 |
2008-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256632
|
- |
|
softacid
|
hotel_reservation_system
|
SQL injection vulnerability in city.asp in SoftAcid Hotel Reservation System (HRS) allows remote attackers to execute arbitrary SQL commands via the city parameter.
|
CWE-89
SQL Injection
|
CVE-2008-4204
|
2017-09-29 10:32 |
2008-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256633
|
- |
|
xmlsoft
|
libxml
|
Integer overflow in the xmlBufferResize function in libxml2 2.7.2 allows context-dependent attackers to cause a denial of service (infinite loop) via a large XML document.
|
CWE-189
Numeric Errors
|
CVE-2008-4225
|
2017-09-29 10:32 |
2008-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256634
|
- |
|
xmlsoft
|
libxml
|
Integer overflow in the xmlSAX2Characters function in libxml2 2.7.2 allows context-dependent attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a large …
|
CWE-399
Resource Management Errors
|
CVE-2008-4226
|
2017-09-29 10:32 |
2008-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256635
|
- |
|
cj
|
ultra_plus
|
SQL injection vulnerability in CJ Ultra Plus 1.0.4 and earlier allows remote attackers to execute arbitrary SQL commands via an SID cookie.
|
CWE-89
SQL Injection
|
CVE-2008-4241
|
2017-09-29 10:32 |
2008-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256636
|
- |
|
epic_games
|
unreal_tournament_3
|
Directory traversal vulnerability in ImageServer (aka UTImageServer) in WebAdmin before 1.7 for Epic Games Unreal Tournament 3 (UT3) 1.3 allows remote attackers to read arbitrary files via a .. (dot …
|
CWE-22
Path Traversal
|
CVE-2008-4243
|
2017-09-29 10:32 |
2008-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256637
|
- |
|
rianxosencabos_cms
|
rianxosencabos_cms
|
Rianxosencabos CMS 0.9 allows remote attackers to bypass authentication and gain administrative access by setting the usuario and pass cookies to 1.
|
CWE-287
Improper Authentication
|
CVE-2008-4244
|
2017-09-29 10:32 |
2008-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256638
|
- |
|
rianxosencabos_cms
|
rianxosencabos_cms
|
The Admin Control Panel in Rianxosencabos CMS 0.9 does not require administrator privileges, which allows remote authenticated users to (1) change a user's privileges, (2) delete a user account, or p…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-4245
|
2017-09-29 10:32 |
2008-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256639
|
- |
|
microsoft
|
windows_mobile
|
Microsoft Windows Mobile 6.0 on HTC Wiza 200 and HTC MDA 8125 devices does not properly handle the first attempt to establish a Bluetooth connection to a peer with a long name, which allows remote at…
|
CWE-20
Improper Input Validation
|
CVE-2008-4295
|
2017-09-29 10:32 |
2008-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256640
|
- |
|
redhat
|
enterprise_linux enterprise_linux_desktop
|
A certain Red Hat patch for tog-pegasus in OpenGroup Pegasus 2.7.0 does not properly configure the PAM tty name, which allows remote authenticated users to bypass intended access restrictions and sen…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-4313
|
2017-09-29 10:32 |
2008-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|