|
285131
|
- |
|
viart
|
viart_shop
|
Cross-site scripting (XSS) vulnerability in manuals_search.php in ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to inject arbitrary web script or HTML via the manuals_search parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2008-6757
|
2018-10-12 05:57 |
2009-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285132
|
- |
|
viart
|
viart_shop
|
Cross-site request forgery (CSRF) vulnerability in cart_save.php in ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to hijack the authentication of arbitrary users for requests that conduc…
|
CWE-352
Origin Validation Error
|
CVE-2008-6758
|
2018-10-12 05:57 |
2009-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285133
|
- |
|
viart
|
viart_shop
|
ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to obtain sensitive information via a URL in the POST_DATA parameter to manuals_search.php, which reveals the installation path in an error …
|
CWE-59
Link Following
|
CVE-2008-6759
|
2018-10-12 05:57 |
2009-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285134
|
- |
|
viart
|
viart_shop
|
ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to obtain sensitive information via an unauthenticated add and save action for a shopping cart in cart_save.php, which reveals the SQL table…
|
CWE-59
Link Following
|
CVE-2008-6760
|
2018-10-12 05:57 |
2009-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285135
|
- |
|
viart
|
viart_shop
|
ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to access the contents of an arbitrary shopping cart via a modified cart_name parameter.
|
NVD-CWE-noinfo
|
CVE-2008-6765
|
2018-10-12 05:57 |
2009-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285136
|
- |
|
viart
|
viart_shop
|
cart_save.php in ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to cause a denial of service (excessive shopping carts) via a flood of requests.
|
NVD-CWE-noinfo
|
CVE-2008-6766
|
2018-10-12 05:57 |
2009-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285137
|
- |
|
htc
|
touch_cruise touch_pro
|
HTC Touch Pro and HTC Touch Cruise vCard allows remote attackers to cause denial of service (CPU consumption, SMS consumption, and connectivity loss) via a flood of vCards to UDP port 9204.
|
NVD-CWE-Other
|
CVE-2008-6775
|
2018-10-12 05:57 |
2009-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285138
|
- |
|
dflabs
|
ptk
|
The get_file_type function in lib/file_content.php in DFLabs PTK 0.1, 0.2, and 1.0 allows remote attackers to execute arbitrary commands via shell metacharacters after an arg1= sequence in a filename…
|
CWE-20
Improper Input Validation
|
CVE-2008-6793
|
2018-10-12 05:57 |
2009-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285139
|
- |
|
eaton
|
network_shutdown_module
|
Eaton MGEOPS Network Shutdown Module before 3.10 Build 13 allows remote attackers to execute arbitrary code by adding a custom action to the MGE frontend via pane_actionbutton.php, and then executing…
|
CWE-287
Improper Authentication
|
CVE-2008-6816
|
2018-10-12 05:57 |
2009-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285140
|
- |
|
a-link
|
wl54ap2 wl54ap3
|
Multiple cross-site request forgery (CSRF) vulnerabilities in the management interface on the A-LINK WL54AP3 and WL54AP2 access points before firmware 1.4.2-eng1 allow remote attackers to hijack the …
|
CWE-352
Origin Validation Error
|
CVE-2008-6823
|
2018-10-12 05:57 |
2009-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|