|
298501
|
- |
|
positive_software
|
h-sphere
|
Cross-site scripting (XSS) vulnerability in actions.php in Positive Software H-Sphere WebShell 4.3.10 allows remote attackers to inject arbitrary web script or HTML via (1) the fn parameter during a …
|
CWE-79
Cross-site Scripting
|
CVE-2008-4447
|
2017-08-8 10:32 |
2008-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298502
|
- |
|
positive_software
|
h-sphere
|
Cross-site request forgery (CSRF) vulnerability in actions.php in Positive Software H-Sphere WebShell 4.3.10 allows remote attackers to perform unauthorized actions as an administrator, including fil…
|
CWE-352
Origin Validation Error
|
CVE-2008-4448
|
2017-08-8 10:32 |
2008-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298503
|
- |
|
apache_friends
|
xampp
|
Cross-site scripting (XSS) vulnerability in adodb.php in XAMPP for Windows 1.6.8 allows remote attackers to inject arbitrary web script or HTML via the (1) dbserver, (2) host, (3) user, (4) password,…
|
CWE-79
Cross-site Scripting
|
CVE-2008-4450
|
2017-08-8 10:32 |
2008-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298504
|
- |
|
extrovert_software
|
thyme
|
SQL injection vulnerability in pick_users.php in the groups module in eXtrovert Thyme 1.3 allows remote attackers to execute arbitrary SQL commands via the uname_search parameter. NOTE: some of thes…
|
CWE-89
SQL Injection
|
CVE-2008-4459
|
2017-08-8 10:32 |
2008-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298505
|
- |
|
gnu
|
ibackup
|
ibackup 2.27 allows local users to overwrite arbitrary files via a symlink attack on temporary files.
|
CWE-59
Link Following
|
CVE-2008-4475
|
2017-08-8 10:32 |
2008-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298506
|
- |
|
sympa
|
sympa
|
sympa.pl in sympa 5.3.4 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/sympa_aliases.$$ temporary file. NOTE: wwsympa.fcgi was also reported, but the issue occurred…
|
CWE-59
Link Following
|
CVE-2008-4476
|
2017-08-8 10:32 |
2008-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298507
|
- |
|
jim_trocki
|
mon
|
alert.d/test.alert in mon 0.99.2 allows local users to overwrite arbitrary files via a symlink attack on the test.alert.log temporary file.
|
CWE-59
Link Following
|
CVE-2008-4477
|
2017-08-8 10:32 |
2008-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298508
|
- |
|
redmine
|
redmine
|
Cross-site scripting (XSS) vulnerability in Redmine 0.7.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2008-4481
|
2017-08-8 10:32 |
2008-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298509
|
- |
|
apache
|
xerces-c\+\+
|
The XML parser in Xerces-C++ before 3.0.0 allows context-dependent attackers to cause a denial of service (stack consumption and crash) via an XML schema definition with a large maxOccurs value, whic…
|
CWE-20
Improper Input Validation
|
CVE-2008-4482
|
2017-08-8 10:32 |
2008-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298510
|
- |
|
bluecoat
|
security_gateway_os
|
Cross-site scripting (XSS) vulnerability in the ICAP patience page in Blue Coat Security Gateway OS (SGOS) 4.2 before 4.2.9, 5.2 before 5.2.5, and 5.3 before 5.3.1.7 allows remote attackers to inject…
|
CWE-79
Cross-site Scripting
|
CVE-2008-4485
|
2017-08-8 10:32 |
2008-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|