262521
|
- |
|
drupal
|
drupal
|
Drupal 5.x before 5.13 and 6.x before 6.7 does not delete all related content when an input format is deleted, which prevents the content from being properly filtered and allows remote attackers to c…
|
CWE-79
Cross-site Scripting
|
CVE-2008-6533
|
2017-08-17 10:29 |
2009-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262522
|
- |
|
7-zip
|
7-zip
|
Unspecified vulnerability in 7-zip before 4.5.7 has unknown impact and remote attack vectors, as demonstrated by the PROTOS GENOME test suite for Archive Formats (c10).
|
NVD-CWE-noinfo
|
CVE-2008-6536
|
2017-08-17 10:29 |
2009-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262523
|
- |
|
dotnetnuke
|
dotnetnuke
|
Unspecified vulnerability in the Skin Manager in DotNetNuke before 4.8.2 allows remote authenticated administrators to perform "server-side execution of application logic" by uploading a static file …
|
NVD-CWE-noinfo
|
CVE-2008-6542
|
2017-08-17 10:29 |
2009-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262524
|
- |
|
dotnetnuke
|
dotnetnuke
|
Per vendor advisory: http://www.dotnetnuke.com/News/SecurityBulletins/SecurityBulletinno13/tabid/1149/Default.aspx
Mitigating factors
* The host user must have added the HTM or HTML file …
|
NVD-CWE-noinfo
|
CVE-2008-6542
|
2017-08-17 10:29 |
2009-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262525
|
- |
|
comscripts
|
quick_classifieds
|
Multiple PHP remote file inclusion vulnerabilities in ComScripts TEAM Quick Classifieds 1.0 via the DOCUMENT_ROOT parameter to (1) index.php3, (2) locate.php3, (3) search_results.php3, (4) classified…
|
CWE-94
Code Injection
|
CVE-2008-6543
|
2017-08-17 10:29 |
2009-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262526
|
- |
|
comscripts
|
web_server_creator_web_portal
|
PHP remote file inclusion vulnerability in news/include/createdb.php in Web Server Creator Web Portal 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the langfile parameter. N…
|
CWE-94
Code Injection
|
CVE-2008-6545
|
2017-08-17 10:29 |
2009-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262527
|
- |
|
formencode
|
formencode
|
schema.py in FormEncode for Python (python-formencode) 1.0 does not apply the chained_validators feature, which allows attackers to bypass intended access restrictions via unknown vectors.
|
CWE-20
Improper Input Validation
|
CVE-2008-6547
|
2017-08-17 10:29 |
2009-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262528
|
- |
|
davidbourrier
|
glossaire
|
Cross-site scripting (XSS) vulnerability in glossaire.php in Glossaire 2.0 allows remote attackers to inject arbitrary web script or HTML via the letter parameter. NOTE: the provenance of this infor…
|
CWE-79
Cross-site Scripting
|
CVE-2008-6550
|
2017-08-17 10:29 |
2009-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262529
|
- |
|
citrix
|
presentation_server_client
|
Citrix Presentation Server Client for Windows before 10.200 does not clear "credential information" from process memory in unspecified circumstances, which might allow local users to gain privileges.
|
CWE-200
Information Exposure
|
CVE-2008-6561
|
2017-08-17 10:29 |
2009-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262530
|
- |
|
jax_scripts
|
jax_linklists
|
Cross-site scripting (XSS) vulnerability in jax_linklists.php in Jack (tR) Jax LinkLists 1.00 allows remote attackers to inject arbitrary web script or HTML via the cat parameter. NOTE: the provenan…
|
CWE-79
Cross-site Scripting
|
CVE-2008-6562
|
2017-08-17 10:29 |
2009-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|