|
285151
|
- |
|
collabtive
|
collabtive
|
Cross-site scripting (XSS) vulnerability in manageproject.php in Collabtive 0.4.8 allows user-assisted remote attackers to inject arbitrary web script or HTML via the project Name, which is not prope…
|
CWE-79
Cross-site Scripting
|
CVE-2008-6946
|
2018-10-12 05:57 |
2009-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285152
|
- |
|
collabtive
|
collabtive
|
Collabtive 0.4.8 allows remote attackers to bypass authentication and create new users, including administrators, via unspecified vectors associated with the added mode in a users action to admin.php.
|
CWE-287
Improper Authentication
|
CVE-2008-6947
|
2018-10-12 05:57 |
2009-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285153
|
- |
|
collabtive
|
collabtive
|
Unrestricted file upload vulnerability in Collabtive 0.4.8 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension and using a text/plain MIME typ…
|
CWE-20
Improper Input Validation
|
CVE-2008-6948
|
2018-10-12 05:57 |
2009-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285154
|
- |
|
collabtive
|
collabtive
|
Multiple cross-site request forgery (CSRF) vulnerabilities in Collabtive 0.4.8 allow remote attackers to hijack the authentication of administrators for requests that (1) submit or edit a new project…
|
CWE-352
Origin Validation Error
|
CVE-2008-6949
|
2018-10-12 05:57 |
2009-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285155
|
- |
|
oovoo
|
oovoo
|
Buffer overflow in oovoo.exe in ooVoo 1.7.1.35, and possibly other versions before 1.7.1.59, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a lon…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2008-6953
|
2018-10-12 05:57 |
2009-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285156
|
- |
|
phpadultsite
|
phpadultsite_cms
|
Cross-site scripting (XSS) vulnerability in as_archives.php in phpAdultSite CMS, possibly 2.3.2, allows remote attackers to inject arbitrary web script or HTML via the results_per_page parameter to i…
|
CWE-79
Cross-site Scripting
|
CVE-2008-6979
|
2018-10-12 05:57 |
2009-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285157
|
- |
|
phpadultsite
|
phpadultsite_cms
|
SQL injection vulnerability in as_archives.php in phpAdultSite CMS, possibly 2.3.2, allows remote attackers to execute arbitrary SQL commands via the results_per_page parameter to index.php. NOTE: s…
|
CWE-89
SQL Injection
|
CVE-2008-6980
|
2018-10-12 05:57 |
2009-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285158
|
- |
|
phpadultsite
|
phpadultsite_cms
|
index.php in phpAdultSite CMS, possibly 2.3.2, allows remote attackers to obtain the full installation path via an invalid results_per_page parameter, which leaks the path in an error message. NOTE:…
|
CWE-200
Information Exposure
|
CVE-2008-6981
|
2018-10-12 05:57 |
2009-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285159
|
- |
|
zen-cart
|
zen_cart
|
Multiple SQL injection vulnerabilities in includes/classes/shopping_cart.php in Zen Cart 1.2.0 through 1.3.8a, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL comma…
|
CWE-89
SQL Injection
|
CVE-2008-6985
|
2018-10-12 05:57 |
2009-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285160
|
- |
|
zen-cart
|
zen_cart
|
SQL injection vulnerability in the actionMultipleAddProduct function in includes/classes/shopping_cart.php in Zen Cart 1.3.0 through 1.3.8a, when magic_quotes_gpc is disabled, allows remote attackers…
|
CWE-89
SQL Injection
|
CVE-2008-6986
|
2018-10-12 05:57 |
2009-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|