|
285091
|
- |
|
igniterealtime
|
openfire
|
Cross-site scripting (XSS) vulnerability in login.jsp in the Admin Console in Openfire 3.6.0a and earlier allows remote attackers to inject arbitrary web script or HTML via the url parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2008-6510
|
2018-10-12 05:57 |
2009-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285092
|
- |
|
igniterealtime
|
openfire
|
Open redirect vulnerability in login.jsp in Openfire 3.6.0a and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the url parameter.
|
CWE-20
Improper Input Validation
|
CVE-2008-6511
|
2018-10-12 05:57 |
2009-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285093
|
- |
|
nick_jenkin
|
newshowler
|
SQL injection vulnerability in NewsHOWLER 1.03 Beta allows remote attackers to execute arbitrary SQL commands via the news_user cookie parameter.
|
CWE-89
SQL Injection
|
CVE-2008-6517
|
2018-10-12 05:57 |
2009-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285094
|
- |
|
devraj_mukherjee
|
openterracotta
|
index.php in Terracotta (aka OpenTerracotta) 0.6.1 allows remote attackers to obtain sensitive information via an invalid File parameter, which reveals the installation path in an error message.
|
CWE-200
Information Exposure
|
CVE-2008-6521
|
2018-10-12 05:57 |
2009-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285095
|
- |
|
devraj_mukherjee
|
openterracotta
|
Multiple directory traversal vulnerabilities in the RenderFile function in ContentRender.class.php in Terracotta (aka OpenTerracotta) 0.6.1, and possibly other versions, allow remote attackers to lis…
|
CWE-22
Path Traversal
|
CVE-2008-6522
|
2018-10-12 05:57 |
2009-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285096
|
- |
|
tmaxsoft
|
jeus
|
NTFS TmaxSoft JEUS 5 before Fix 26 allows remote attackers to read the source code for scripts by appending ::$DATA to the URL, which accesses the alternate data stream.
|
CWE-20
Improper Input Validation
|
CVE-2008-6528
|
2018-10-12 05:57 |
2009-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285097
|
- |
|
dotnetnuke
|
dotnetnuke
|
DotNetNuke before 4.8.2, during installation or upgrade, does not warn the administrator when the default (1) ValidationKey and (2) DecryptionKey values cannot be modified in the web.config file, whi…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-6540
|
2018-10-12 05:57 |
2009-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285098
|
- |
|
aztech
|
adsl2\/2\+4-port_router
|
cgi-bin/script in Aztech ADSL2/2+ 4-port router 3.7.0 build 070426 allows remote attackers to execute arbitrary commands via shell metacharacters in the query string.
|
CWE-78
OS Command
|
CVE-2008-6554
|
2018-10-12 05:57 |
2009-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285099
|
- |
|
puppetmaster
|
webutil
|
cgi-bin/webutil.pl in The Puppet Master WebUtil allows remote attackers to execute arbitrary commands via shell metacharacters in the dig command.
|
CWE-20
Improper Input Validation
|
CVE-2008-6555
|
2018-10-12 05:57 |
2009-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285100
|
- |
|
puppet_master
|
webutil
|
cgi-bin/webutil.pl in The Puppet Master WebUtil 2.3 allows remote attackers to execute arbitrary commands via shell metacharacters in the whois command.
|
CWE-20
Improper Input Validation
|
CVE-2008-6556
|
2018-10-12 05:57 |
2009-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|