|
284301
|
- |
|
vmware
|
ace player vmware_player vmware_workstation workstation
|
Directory traversal vulnerability in the Shared Folders feature for VMWare ACE 1.0.2 and 2.0.2, Player 1.0.4 and 2.0.2, and Workstation 5.5.4 and 6.0.2 allows guest OS users to read and write arbitra…
|
CWE-22
Path Traversal
|
CVE-2008-0923
|
2018-10-16 07:03 |
2008-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284302
|
- |
|
novell
|
edirectory
|
The SOAP interface to the eMBox module in Novell eDirectory 8.7.3.9 and earlier, and 8.8.x before 8.8.2, relies on client-side authentication, which allows remote attackers to bypass authentication v…
|
CWE-287
Improper Authentication
|
CVE-2008-0926
|
2018-10-16 07:03 |
2008-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284303
|
- |
|
aeries
|
aeries_student_information_system
|
Cross-site scripting (XSS) vulnerability in Eagle Software Aeries Browser Interface (ABI) 3.8.2.8 allows remote authenticated users to inject arbitrary web script or HTML via an event.
|
CWE-79
Cross-site Scripting
|
CVE-2008-0941
|
2018-10-16 07:03 |
2008-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284304
|
- |
|
aeries
|
aeries_student_information_system
|
SQL injection vulnerability in GradebookStuScores.asp in Eagle Software Aeries Browser Interface (ABI) 3.8.2.8 allows remote attackers to execute arbitrary SQL commands via the GrdBk parameter.
|
CWE-89
SQL Injection
|
CVE-2008-0942
|
2018-10-16 07:03 |
2008-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284305
|
- |
|
aeries
|
aeries_student_information_system
|
Multiple SQL injection vulnerabilities in Eagle Software Aeries Browser Interface (ABI) 3.7.2.2 allow remote attackers to execute arbitrary SQL commands via the (1) FC parameter to Comments.asp, or t…
|
CWE-89
SQL Injection
|
CVE-2008-0943
|
2018-10-16 07:03 |
2008-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284306
|
- |
|
ipswitch
|
instant_messaging
|
Ipswitch Instant Messaging (IM) 2.0.8.1 and earlier allows remote attackers to cause a denial of service (NULL dereference and application crash) via a version field containing zero.
|
CWE-189
Numeric Errors
|
CVE-2008-0944
|
2018-10-16 07:03 |
2008-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284307
|
- |
|
ipswitch
|
imserver instant_messaging
|
Format string vulnerability in the logging function in the IM Server (aka IMserve or IMserver) in Ipswitch Instant Messaging (IM) 2.0.8.1 and earlier allows remote authenticated users to cause a deni…
|
CWE-134
Use of Externally-Controlled Format String
|
CVE-2008-0945
|
2018-10-16 07:03 |
2008-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284308
|
- |
|
ipswitch
|
imserver instant_messaging
|
Directory traversal vulnerability in the IM Server (aka IMserve or IMserver) in Ipswitch Instant Messaging (IM) 2.0.8.1 and earlier allows remote authenticated users to create arbitrary empty files v…
|
CWE-22
Path Traversal
|
CVE-2008-0946
|
2018-10-16 07:03 |
2008-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284309
|
- |
|
barracuda_networks
|
barracuda_im_firewall barracuda_load_balancer barracuda_message_archiver barracuda_spam_firewall barracuda_web_filter
|
Multiple cross-site scripting (XSS) vulnerabilities in index.cgi in Barracuda Spam Firewall (BSF) before 3.5.12.007, Message Archiver before 1.2.1.002, Web Filter before 3.3.0.052, IM Firewall before…
|
CWE-79
Cross-site Scripting
|
CVE-2008-0971
|
2018-10-16 07:03 |
2008-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284310
|
- |
|
astrosoft
|
astrosoft_helpdesk
|
Multiple cross-site scripting (XSS) vulnerabilities in AstroSoft HelpDesk before 1.95.228 allow remote attackers to inject arbitrary web script or HTML via the (1) txtSearch parameter to operator/art…
|
CWE-79
Cross-site Scripting
|
CVE-2008-0605
|
2018-10-16 07:02 |
2008-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|