|
297721
|
- |
|
michael_dehaan
|
cobbler
|
The web interface (CobblerWeb) in Cobbler before 1.2.9 allows remote authenticated users to execute arbitrary Python code in cobblerd by editing a Cheetah kickstart template to import arbitrary Pytho…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-6954
|
2017-08-17 10:29 |
2009-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
297722
|
- |
|
avira
|
antivir antivir_personal antivir_professional antivir_security_suite
|
Avira AntiVir Premium, Premium Security Suite, AntiVir Professional, and AntiVir Personal - FREE allows local users to execute arbitrary code via a crafted IOCTL request that overwrites a kernel poin…
|
CWE-20
Improper Input Validation
|
CVE-2008-6962
|
2017-08-17 10:29 |
2009-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
297723
|
- |
|
alt-n
|
mdaemon worldclient
|
Multiple unspecified vulnerabilities in WorldClient in Alt-N MDaemon before 10.02 have unknown impact and attack vectors, probably related to cross-site scripting (XSS) and WorldClient DLL 10.0.1, a …
|
NVD-CWE-noinfo
|
CVE-2008-6967
|
2017-08-17 10:29 |
2009-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
297724
|
- |
|
pligg
|
pligg_cms
|
Multiple SQL injection vulnerabilities in submit.php in Pligg CMS 9.9.5 allow remote attackers to execute arbitrary SQL commands via the (1) category and (2) id parameters.
|
CWE-89
SQL Injection
|
CVE-2008-6968
|
2017-08-17 10:29 |
2009-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
297725
|
- |
|
pentasoft_corp.
|
avactis_shopping_cart
|
Multiple cross-site scripting (XSS) vulnerabilities in checkout.php in Avactis Shopping Cart 1.8.0 and 1.8.1 allow remote attackers to inject arbitrary web script or HTML via the (1) step_id and (2) …
|
CWE-79
Cross-site Scripting
|
CVE-2008-6969
|
2017-08-17 10:29 |
2009-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
297726
|
- |
|
ubbcentral
|
ubb.threads
|
SQL injection vulnerability in dosearch.inc.php in UBB.threads 7.3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the Forum[] array parameter.
|
CWE-89
SQL Injection
|
CVE-2008-6970
|
2017-08-17 10:29 |
2009-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
297727
|
- |
|
karen_stevenson yves_chedemois
|
cck
|
Multiple cross-site scripting (XSS) vulnerabilities in Drupal Content Construction Kit (CCK) 5.x through 5.x-1.8 allow remote authenticated users with "administer content" permissions to inject arbit…
|
CWE-79
Cross-site Scripting
|
CVE-2008-6972
|
2017-08-17 10:29 |
2009-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
297728
|
- |
|
ibm
|
websphere_commerce
|
Multiple unspecified vulnerabilities in IBM WebSphere Commerce 6.0 before 6.0.0.7 have unknown impact and attack vectors.
|
NVD-CWE-noinfo
|
CVE-2008-6973
|
2017-08-17 10:29 |
2009-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
297729
|
- |
|
parallels
|
plesk
|
Plesk 8.6.0, when short mail login names (SHORTNAMES) are enabled, allows remote attackers to bypass authentication and send spam e-mail via a message with (1) a base64-encoded username that begins w…
|
CWE-287
Improper Authentication
|
CVE-2008-6984
|
2017-08-17 10:29 |
2009-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
297730
|
- |
|
ezonescripts
|
dating_website_script
|
Unrestricted file upload vulnerability in eZoneScripts Dating Website script allows remote attackers to execute arbitrary code via unknown vectors. NOTE: the provenance of this information is unknow…
|
NVD-CWE-Other
|
CVE-2008-6987
|
2017-08-17 10:29 |
2009-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|