|
303331
|
- |
|
apple
|
mac_os_x mac_os_x_server
|
Cross-site request forgery (CSRF) vulnerability in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before 10.6.4, and other platforms, allows remote attackers …
|
CWE-352
Origin Validation Error
|
CVE-2010-0540
|
2024-11-21 10:12 |
2010-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303332
|
6.1 |
MEDIUM
Network
|
invisioncommunity microsoft
|
invision_power_board internet_explorer
|
Invision Power Board (aka IPB or IP.Board) 2.x through 3.0.4, when Internet Explorer 5 is used, allows XSS via a .txt attachment.
|
CWE-79
Cross-site Scripting
|
CVE-2009-5159
|
2024-11-21 10:11 |
2020-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303333
|
8.8 |
HIGH
Network
|
linksys
|
spa2102_firmware
|
The SIP implementation on the Linksys SPA2102 phone adapter provides hashed credentials in a response to an invalid authentication challenge, which makes it easier for remote attackers to obtain acce…
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2009-5140
|
2024-11-21 10:11 |
2020-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303334
|
7.5 |
HIGH
Network
|
google
|
gizmo5
|
The SIP implementation on the Gizmo5 software phone provides hashed credentials in a response to an invalid authentication challenge, which makes it easier for remote attackers to obtain access via a…
|
CWE-916
Use of Password Hash With Insufficient Computational Effort
|
CVE-2009-5139
|
2024-11-21 10:11 |
2020-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303335
|
7.2 |
HIGH
Network
|
simplemachines
|
simple_machines_forum
|
There is a file disclosure vulnerability in SMF (Simple Machines Forum) affecting versions through v2.0.3. On some configurations a SMF deployment is shared by several "co-admins" that are not truste…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2009-5068
|
2024-11-21 10:11 |
2020-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303336
|
7.5 |
HIGH
Network
|
pyforum_project
|
pyforum
|
A backdoor (aka BMSA-2009-07) was found in PyForum v1.0.3 where an attacker who knows a valid user email could force a password reset on behalf of that user.
|
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
|
CVE-2009-5025
|
2024-11-21 10:11 |
2020-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303337
|
6.1 |
MEDIUM
Network
|
eclipse debian
|
jetty debian_linux
|
JSP Dump and Session Dump Servlet XSS in jetty before 6.1.22.
|
CWE-79
Cross-site Scripting
|
CVE-2009-5046
|
2024-11-21 10:11 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303338
|
7.5 |
HIGH
Network
|
eclipse debian
|
jetty debian_linux
|
Dump Servlet information leak in jetty before 6.1.22.
|
CWE-200
Information Exposure
|
CVE-2009-5045
|
2024-11-21 10:11 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303339
|
7.5 |
HIGH
Network
|
konversation
|
konversation
|
konversation before 1.2.3 allows attackers to cause a denial of service.
|
CWE-20
Improper Input Validation
|
CVE-2009-5050
|
2024-11-21 10:11 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303340
|
6.1 |
MEDIUM
Network
|
mortbay debian
|
jetty debian_linux
|
WebApp JSP Snoop page XSS in jetty though 6.1.21.
|
CWE-79
Cross-site Scripting
|
CVE-2009-5049
|
2024-11-21 10:11 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|