260981
|
- |
|
mozilo
|
mozilowiki
|
Session fixation vulnerability in moziloWiki 1.0.1 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.
|
CWE-287
Improper Authentication
|
CVE-2008-6131
|
2017-08-17 10:29 |
2009-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260982
|
- |
|
drupal
|
everyblog
|
SQL injection vulnerability in EveryBlog 5.x and 6.x, a module for Drupal, allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
|
CWE-89
SQL Injection
|
CVE-2008-6134
|
2017-08-17 10:29 |
2009-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260983
|
- |
|
drupal
|
everyblog
|
Cross-site scripting (XSS) vulnerability in EveryBlog 5.x and 6.x, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2008-6135
|
2017-08-17 10:29 |
2009-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260984
|
- |
|
drupal
|
everyblog
|
Unspecified vulnerability in EveryBlog 5.x and 6.x, a module for Drupal, allows remote attackers to gain privileges as another user or an administrator via unknown attack vectors.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-6136
|
2017-08-17 10:29 |
2009-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260985
|
- |
|
drupal
|
everyblog
|
EveryBlog 5.x and 6.x, a module for Drupal, allows remote attackers to bypass access restrictions via unknown vectors.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-6137
|
2017-08-17 10:29 |
2009-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260986
|
- |
|
avaya
|
one-x
|
Unspecified vulnerability in the Session Initiation Protocol (SIP) implementation in Avaya one-X Desktop Edition 2.1.0.78 allows remote attackers to cause a denial of service (crash) via unspecified …
|
NVD-CWE-noinfo
|
CVE-2008-6140
|
2017-08-17 10:29 |
2009-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260987
|
- |
|
avaya
|
ip_soft_phone
|
Unspecified vulnerability in Avaya IP Softphone 6.0 SP4 and 6.01.85 allows remote attackers to cause a denial of service (crash) via a large amount of H.323 data.
|
CWE-399
Resource Management Errors
|
CVE-2008-6141
|
2017-08-17 10:29 |
2009-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260988
|
- |
|
hispah
|
text_links_ads
|
SQL injection vulnerability in index.php in Hispah Text Links Ads 1.1 allows remote attackers to execute arbitrary SQL commands via the idtl parameter in a buy action. NOTE: the provenance of this i…
|
CWE-89
SQL Injection
|
CVE-2008-6155
|
2017-08-17 10:29 |
2009-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260989
|
- |
|
w3bcms
|
w3b\>cms
|
Multiple unspecified vulnerabilities in the admin backend in w3b>cms (aka w3blabor CMS) before 3.2.0 have unknown impact and remote attack vectors.
|
NVD-CWE-noinfo
|
CVE-2008-6158
|
2017-08-17 10:29 |
2009-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260990
|
- |
|
drupal
|
semantically_interconnected_online_communities
|
Semantically-Interconnected Online Communities (SIOC) 5.x before 5.x-1.2 and 6.x before 6.x-1.1, a module for Drupal, does not properly implement menu and database APIs, which allows remote attackers…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-6160
|
2017-08-17 10:29 |
2009-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|