|
297981
|
- |
|
holloway
|
docvert
|
test-pipe-to-pyodconverter.org.sh in docvert 2.4 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/outer.odt temporary file.
|
CWE-59
Link Following
|
CVE-2008-5147
|
2017-08-8 10:33 |
2008-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
297982
|
- |
|
jose_carlos_medeiros
|
maildirsync
|
sample.sh in maildirsync 1.1 allows local users to append data to arbitrary files via a symlink attack on a /tmp/maildirsync-*.#####.log temporary file.
|
CWE-59
Link Following
|
CVE-2008-5150
|
2017-08-8 10:33 |
2008-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
297983
|
- |
|
peter_s_galbraith
|
mh-book
|
inmail-show in mh-book 200605 allows local users to overwrite arbitrary files via a symlink attack on a (1) /tmp/inmail#####.log or (2) /tmp/inmail#####.stdin temporary file.
|
CWE-59
Link Following
|
CVE-2008-5152
|
2017-08-8 10:33 |
2008-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
297984
|
- |
|
moodle
|
moodle
|
spell-check-logic.cgi in Moodle 1.8.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/spell-check-debug.log, (2) /tmp/spell-check-before, or (3) /tmp/spell-check-…
|
CWE-59
Link Following
|
CVE-2008-5153
|
2017-08-8 10:33 |
2008-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
297985
|
- |
|
koeniglich
|
p3nfs
|
bluetooth.rc in p3nfs 5.19 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/blue.log temporary file.
|
CWE-59
Link Following
|
CVE-2008-5154
|
2017-08-8 10:33 |
2008-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
297986
|
- |
|
uoregon
|
tau
|
tau 2.16.4 allows local users to overwrite arbitrary files via a symlink attack on a (1) /tmp/makefile.tau.*.##### or (2) /tmp/makefile.tau*.##### temporary file, related to the (a) tau_cxx, (b) tau_…
|
CWE-59
Link Following
|
CVE-2008-5157
|
2017-08-8 10:33 |
2008-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
297987
|
- |
|
eticket
|
eticket
|
Multiple SQL injection vulnerabilities in eTicket 1.5.7 allow remote attackers to execute arbitrary SQL commands via the pri parameter to (1) index.php, (2) open.php, (3) open_raw.php, and (4) newtic…
|
CWE-89
SQL Injection
|
CVE-2008-5165
|
2017-08-8 10:33 |
2008-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
297988
|
- |
|
forumsoftware
|
yazd_forum_software
|
Multiple cross-site scripting (XSS) vulnerabilities in Yazd Forum Software 3.x allow remote attackers to inject arbitrary web script or HTML via the (1) q parameter to (a) search.jsp, and the (2) msg…
|
CWE-79
Cross-site Scripting
|
CVE-2008-5172
|
2017-08-8 10:33 |
2008-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
297989
|
- |
|
testmaker
|
testmaker
|
Unspecified vulnerability in testMaker before 3.0p16 allows remote authenticated users to execute arbitrary PHP code via unspecified attack vectors.
|
NVD-CWE-noinfo CWE-94
Code Injection
|
CVE-2008-5173
|
2017-08-8 10:33 |
2008-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
297990
|
- |
|
visicommedia
|
aceftp
|
Directory traversal vulnerability in the FTP client in AceFTP Freeware 3.80.3 and AceFTP Pro 3.80.3 allows remote FTP servers to create or overwrite arbitrary files via a .. (dot dot) in a response t…
|
CWE-22
Path Traversal
|
CVE-2008-5175
|
2017-08-8 10:33 |
2008-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|