|
285011
|
- |
|
mybboard
|
mybb
|
MyBB (aka MyBulletinBoard) 1.4.3 includes the sensitive my_post_key parameter in URLs to moderation.php with the (1) mergeposts, (2) split, and (3) deleteposts actions, which allows remote attackers …
|
CWE-352
Origin Validation Error
|
CVE-2008-7082
|
2018-10-12 05:58 |
2009-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285012
|
- |
|
hirschelectronics
|
velocity_security_management_system
|
Directory traversal vulnerability in the web server 1.0 in Velocity Security Management System allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.
|
CWE-22
Path Traversal
|
CVE-2008-7084
|
2018-10-12 05:58 |
2009-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285013
|
- |
|
openpro
|
openpro
|
PHP remote file inclusion vulnerability in search_wA.php in OpenPro 1.3.1 allows remote attackers to execute arbitrary PHP code via a URL in the LIBPATH parameter.
|
CWE-94
Code Injection
|
CVE-2008-7087
|
2018-10-12 05:58 |
2009-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285014
|
- |
|
pligg
|
pligg_cms
|
Cross-site scripting (XSS) vulnerability in Pligg 9.9 and earlier allows remote attackers to inject arbitrary web script or HTML via the keyword parameter in a search action to user.php and other uns…
|
CWE-79
Cross-site Scripting
|
CVE-2008-7089
|
2018-10-12 05:58 |
2009-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285015
|
- |
|
pligg
|
pligg_cms
|
Multiple directory traversal vulnerabilities in Pligg 9.9 and earlier allow remote attackers to (1) determine the existence of arbitrary files via a .. (dot dot) in the $tb_url variable in trackback.…
|
CWE-22
Path Traversal
|
CVE-2008-7090
|
2018-10-12 05:58 |
2009-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285016
|
- |
|
pligg
|
pligg_cms
|
Multiple SQL injection vulnerabilities in Pligg 9.9 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to vote.php, which is not properly handled in libs/li…
|
CWE-89
SQL Injection
|
CVE-2008-7091
|
2018-10-12 05:58 |
2009-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285017
|
- |
|
arubanetworks
|
aruba_mobility_controller arubaos
|
The SNMP daemon in ArubaOS 3.3.2.6 in Aruba Mobility Controller does not restrict SNMP access, which allows remote attackers to (1) read all SNMP community strings via SNMP-COMMUNITY-MIB::snmpCommuni…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-7095
|
2018-10-12 05:58 |
2009-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285018
|
- |
|
phpcart
|
phpcart
|
Multiple cross-site scripting (XSS) vulnerabilities in Carmosa phpCart 3.4 through 4.6.4 allow remote attackers to inject arbitrary web script or HTML via the (1) quantity or (2) Add Engraving fields…
|
CWE-79
Cross-site Scripting
|
CVE-2008-7108
|
2018-10-12 05:58 |
2009-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285019
|
- |
|
kyoceramita
|
scanner_file_utility
|
Directory traversal vulnerability in the Scanner File Utility (aka listener) in Kyocera Mita (KM) 3.3.0.1 allows remote attackers to upload files to arbitrary locations via a .. (dot dot) in a reques…
|
CWE-22
Path Traversal
|
CVE-2008-7110
|
2018-10-12 05:58 |
2009-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285020
|
- |
|
kyoceramita
|
scanner_file_utility
|
The Scanner File Utility (aka listener) in Kyocera Mita (KM) 3.3.0.1 does not restrict the filenames or extensions of uploaded files, which makes it easier for remote attackers to execute arbitrary c…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-7111
|
2018-10-12 05:58 |
2009-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|