|
303681
|
9.8 |
CRITICAL
Network
|
cpan
|
ui\
|
UI-Dialog 1.09 and earlier allows remote attackers to execute arbitrary commands.
|
CWE-77
Command Injection
|
CVE-2008-7315
|
2024-11-21 09:58 |
2017-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303682
|
9.8 |
CRITICAL
Network
|
snoopy redhat nagios
|
snoopy openstack nagios
|
The _httpsrequest function in Snoopy allows remote attackers to execute arbitrary commands. NOTE: this issue exists dues to an incomplete fix for CVE-2008-4796.
|
CWE-77
Command Injection
|
CVE-2008-7313
|
2024-11-21 09:58 |
2017-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303683
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
mm/filemap.c in the Linux kernel before 2.6.25 allows local users to cause a denial of service (infinite loop) via a writev system call that triggers an iovec of zero length, followed by a page fault…
|
CWE-20
Improper Input Validation
|
CVE-2008-7316
|
2024-11-21 09:58 |
2016-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303684
|
- |
|
websense
|
enterprise
|
The Filtering Service in Websense Enterprise 5.2 through 6.3 does not consider the IP address during URL categorization, which makes it easier for remote attackers to bypass filtering via an HTTP req…
|
CWE-20
Improper Input Validation
|
CVE-2008-7312
|
2024-11-21 09:58 |
2012-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303685
|
- |
|
spreecommerce
|
spree
|
The session cookie store implementation in Spree 0.2.0 uses a hardcoded config.action_controller_session hash value (aka secret key), which makes it easier for remote attackers to bypass cryptographi…
|
CWE-255
Credentials Management
|
CVE-2008-7311
|
2024-11-21 09:58 |
2012-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303686
|
- |
|
spreecommerce
|
spree
|
Spree 0.2.0 does not properly restrict the use of a hash to provide values for a model's attributes, which allows remote attackers to set the Order state value and bypass the intended payment step vi…
|
CWE-255
Credentials Management
|
CVE-2008-7310
|
2024-11-21 09:58 |
2012-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303687
|
- |
|
insoshi
|
insoshi
|
Insoshi before 20080920 does not properly restrict the use of a hash to provide values for a model's attributes, which allows remote attackers to set the ForumPost user_id value via a modified URL, r…
|
CWE-255
Credentials Management
|
CVE-2008-7309
|
2024-11-21 09:58 |
2012-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303688
|
- |
|
apple
|
mac_os_x
|
The nonet and nointernet sandbox profiles in Apple Mac OS X 10.5.x do not propagate restrictions to all created processes, which allows remote attackers to access network resources via a crafted appl…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-7303
|
2024-11-21 09:58 |
2011-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303689
|
- |
|
netshinesoftware
|
com_netinvoice
|
SQL injection vulnerability in netinvoice.php in the nBill (com_netinvoice) component 1.2.0 SP1 for Joomla! allows remote attackers to execute arbitrary SQL commands via unspecified vectors involving…
|
CWE-89
SQL Injection
|
CVE-2008-7302
|
2024-11-21 09:58 |
2011-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303690
|
- |
|
sclek
|
jsite
|
SQL injection vulnerability in admin/login.php in jSite 1.0 OE allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: the provenance of this information is unkno…
|
CWE-89
SQL Injection
|
CVE-2008-7301
|
2024-11-21 09:58 |
2011-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|