Логотип exploitDog
source:"nvd"
Консоль
Логотип exploitDog

exploitDog

source:"nvd"

Количество 331 614

Количество 331 614

nvd логотип

CVE-2008-0410

около 18 лет назад

HTTP File Server (HFS) before 2.2c allows remote attackers to obtain configuration and usage details by using an id element such as <id>%version%</id> in HTTP Basic Authentication instead of a username and password, as demonstrated by placing this id element in the userinfo subcomponent of a URL.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2008-0409

около 18 лет назад

Cross-site scripting (XSS) vulnerability in HTTP File Server (HFS) before 2.2c allows remote attackers to inject arbitrary web script or HTML via the userinfo subcomponent of a URL.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2008-0408

около 18 лет назад

HTTP File Server (HFS) before 2.2c allows remote attackers to append arbitrary text to the log file by using the base64 representation of this text during HTTP Basic Authentication.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2008-0407

около 18 лет назад

HTTP File Server (HFS) before 2.2c tags HTTP request log entries with the username sent during HTTP Basic Authentication, regardless of whether authentication succeeded, which might make it more difficult for an administrator to determine who made a remote request.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2008-0406

около 18 лет назад

HTTP File Server (HFS) before 2.2c, when account names are used as log filenames, allows remote attackers to cause a denial of service (daemon crash) via a long account name.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2008-0405

около 18 лет назад

Multiple directory traversal vulnerabilities in HTTP File Server (HFS) before 2.2c, when account names are used as log filenames, allow remote attackers to create arbitrary (1) files and (2) directories via a .. (dot dot) in an account name, when requesting the / URI; and (3) append arbitrary data to a file via a .. (dot dot) in an account name, when requesting a URI composed of a "/?%0a" sequence followed by the data.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2008-0404

около 18 лет назад

Cross-site scripting (XSS) vulnerability in Mantis before 1.1.1 allows remote attackers to inject arbitrary web script or HTML via vectors related to the "Most active bugs" summary.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2008-0403

около 18 лет назад

The web server in Belkin Wireless G Plus MIMO Router F5D9230-4 does not require authentication for SaveCfgFile.cgi, which allows remote attackers to read and modify configuration via a direct request to SaveCfgFile.cgi.

CVSS2: 5.5
EPSS: Средний
nvd логотип

CVE-2008-0402

около 18 лет назад

Unspecified vulnerability in IBM WebSphere Business Modeler Basic and Advanced 6.0.2.1 before Interim Fix 11 allows remote authenticated users to bypass intended access restrictions and delete unspecified repository resources via unknown vectors, even when they are not administrators or members of the repository's owning group.

CVSS2: 6
EPSS: Низкий
nvd логотип

CVE-2008-0401

около 18 лет назад

Buffer overflow in the logging functionality of the HTTP server in IBM Tivoli Provisioning Manager for OS Deployment (TPMfOSD) before 5.1.0.3 Interim Fix 3 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via an HTTP request with a long method string to port 443/tcp.

CVSS2: 10
EPSS: Средний
nvd логотип

CVE-2008-0400

около 18 лет назад

Cross-site scripting (XSS) vulnerability in header.tpl.php in the modern template for Singapore 0.10.1 allows remote attackers to inject arbitrary web script or HTML via the gallery parameter to default.php.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2008-0399

около 18 лет назад

Multiple buffer overflows in Toshiba Surveillance (Surveillix) RecordSend ActiveX control (MeIpCamX.DLL 1.0.0.4) allow remote attackers to execute arbitrary code via long arguments to the (1) SetPort and (2) SetIpAddress methods.

CVSS2: 6.8
EPSS: Средний
nvd логотип

CVE-2008-0398

около 18 лет назад

Cross-site scripting (XSS) vulnerability in aflog 1.01, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the comment form.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2008-0397

около 18 лет назад

Multiple SQL injection vulnerabilities in aflog 1.01, and possibly earlier versions, allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to comments.php and (2) an unspecified parameter to view.php.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2008-0396

около 18 лет назад

Directory traversal vulnerability in BitDefender Update Server (http.exe), as used in BitDefender products including Security for Fileservers and Enterprise Manager (BDEM), allows remote attackers to read arbitrary files via .. (dot dot) sequences in an HTTP request.

CVSS2: 7.8
EPSS: Низкий
nvd логотип

CVE-2008-0395

около 18 лет назад

Kayako SupportSuite 3.11.01 allows remote attackers to obtain server configuration information via a direct request to syncml/index.php, which prints the contents of the $_SERVER superglobal.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2008-0394

около 18 лет назад

Buffer overflow in Citadel SMTP server 7.10 and earlier allows remote attackers to execute arbitrary code via a long RCPT TO command, which is not properly handled by the makeuserkey function. NOTE: some of these details were obtained from third party information.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2008-0393

около 18 лет назад

Directory traversal vulnerability in info.php in GradMan 0.1.3 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the tabla parameter, a different vector than CVE-2008-0361.

CVSS2: 5.8
EPSS: Низкий
nvd логотип

CVE-2008-0392

около 18 лет назад

Multiple buffer overflows in Microsoft Visual Basic Enterprise Edition 6.0 SP6 allow user-assisted remote attackers to execute arbitrary code via a .dsr file with a long (1) ConnectionName or (2) CommandName line.

CVSS2: 9.3
EPSS: Средний
nvd логотип

CVE-2008-0391

около 18 лет назад

inc/elementz.php in aliTalk 1.9.1.1 does not properly verify authentication, which allows remote attackers to add an arbitrary user account via a modified lilil parameter, in conjunction with the ubild and pa parameters.

CVSS2: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2008-0410

HTTP File Server (HFS) before 2.2c allows remote attackers to obtain configuration and usage details by using an id element such as <id>%version%</id> in HTTP Basic Authentication instead of a username and password, as demonstrated by placing this id element in the userinfo subcomponent of a URL.

CVSS2: 5
1%
Низкий
около 18 лет назад
nvd логотип
CVE-2008-0409

Cross-site scripting (XSS) vulnerability in HTTP File Server (HFS) before 2.2c allows remote attackers to inject arbitrary web script or HTML via the userinfo subcomponent of a URL.

CVSS2: 4.3
1%
Низкий
около 18 лет назад
nvd логотип
CVE-2008-0408

HTTP File Server (HFS) before 2.2c allows remote attackers to append arbitrary text to the log file by using the base64 representation of this text during HTTP Basic Authentication.

CVSS2: 6.4
1%
Низкий
около 18 лет назад
nvd логотип
CVE-2008-0407

HTTP File Server (HFS) before 2.2c tags HTTP request log entries with the username sent during HTTP Basic Authentication, regardless of whether authentication succeeded, which might make it more difficult for an administrator to determine who made a remote request.

CVSS2: 5
0%
Низкий
около 18 лет назад
nvd логотип
CVE-2008-0406

HTTP File Server (HFS) before 2.2c, when account names are used as log filenames, allows remote attackers to cause a denial of service (daemon crash) via a long account name.

CVSS2: 5
8%
Низкий
около 18 лет назад
nvd логотип
CVE-2008-0405

Multiple directory traversal vulnerabilities in HTTP File Server (HFS) before 2.2c, when account names are used as log filenames, allow remote attackers to create arbitrary (1) files and (2) directories via a .. (dot dot) in an account name, when requesting the / URI; and (3) append arbitrary data to a file via a .. (dot dot) in an account name, when requesting a URI composed of a "/?%0a" sequence followed by the data.

CVSS2: 10
1%
Низкий
около 18 лет назад
nvd логотип
CVE-2008-0404

Cross-site scripting (XSS) vulnerability in Mantis before 1.1.1 allows remote attackers to inject arbitrary web script or HTML via vectors related to the "Most active bugs" summary.

CVSS2: 4.3
1%
Низкий
около 18 лет назад
nvd логотип
CVE-2008-0403

The web server in Belkin Wireless G Plus MIMO Router F5D9230-4 does not require authentication for SaveCfgFile.cgi, which allows remote attackers to read and modify configuration via a direct request to SaveCfgFile.cgi.

CVSS2: 5.5
10%
Средний
около 18 лет назад
nvd логотип
CVE-2008-0402

Unspecified vulnerability in IBM WebSphere Business Modeler Basic and Advanced 6.0.2.1 before Interim Fix 11 allows remote authenticated users to bypass intended access restrictions and delete unspecified repository resources via unknown vectors, even when they are not administrators or members of the repository's owning group.

CVSS2: 6
0%
Низкий
около 18 лет назад
nvd логотип
CVE-2008-0401

Buffer overflow in the logging functionality of the HTTP server in IBM Tivoli Provisioning Manager for OS Deployment (TPMfOSD) before 5.1.0.3 Interim Fix 3 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via an HTTP request with a long method string to port 443/tcp.

CVSS2: 10
26%
Средний
около 18 лет назад
nvd логотип
CVE-2008-0400

Cross-site scripting (XSS) vulnerability in header.tpl.php in the modern template for Singapore 0.10.1 allows remote attackers to inject arbitrary web script or HTML via the gallery parameter to default.php.

CVSS2: 4.3
0%
Низкий
около 18 лет назад
nvd логотип
CVE-2008-0399

Multiple buffer overflows in Toshiba Surveillance (Surveillix) RecordSend ActiveX control (MeIpCamX.DLL 1.0.0.4) allow remote attackers to execute arbitrary code via long arguments to the (1) SetPort and (2) SetIpAddress methods.

CVSS2: 6.8
13%
Средний
около 18 лет назад
nvd логотип
CVE-2008-0398

Cross-site scripting (XSS) vulnerability in aflog 1.01, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the comment form.

CVSS2: 4.3
3%
Низкий
около 18 лет назад
nvd логотип
CVE-2008-0397

Multiple SQL injection vulnerabilities in aflog 1.01, and possibly earlier versions, allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to comments.php and (2) an unspecified parameter to view.php.

CVSS2: 6.8
0%
Низкий
около 18 лет назад
nvd логотип
CVE-2008-0396

Directory traversal vulnerability in BitDefender Update Server (http.exe), as used in BitDefender products including Security for Fileservers and Enterprise Manager (BDEM), allows remote attackers to read arbitrary files via .. (dot dot) sequences in an HTTP request.

CVSS2: 7.8
8%
Низкий
около 18 лет назад
nvd логотип
CVE-2008-0395

Kayako SupportSuite 3.11.01 allows remote attackers to obtain server configuration information via a direct request to syncml/index.php, which prints the contents of the $_SERVER superglobal.

CVSS2: 5
0%
Низкий
около 18 лет назад
nvd логотип
CVE-2008-0394

Buffer overflow in Citadel SMTP server 7.10 and earlier allows remote attackers to execute arbitrary code via a long RCPT TO command, which is not properly handled by the makeuserkey function. NOTE: some of these details were obtained from third party information.

CVSS2: 7.5
13%
Средний
около 18 лет назад
nvd логотип
CVE-2008-0393

Directory traversal vulnerability in info.php in GradMan 0.1.3 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the tabla parameter, a different vector than CVE-2008-0361.

CVSS2: 5.8
4%
Низкий
около 18 лет назад
nvd логотип
CVE-2008-0392

Multiple buffer overflows in Microsoft Visual Basic Enterprise Edition 6.0 SP6 allow user-assisted remote attackers to execute arbitrary code via a .dsr file with a long (1) ConnectionName or (2) CommandName line.

CVSS2: 9.3
51%
Средний
около 18 лет назад
nvd логотип
CVE-2008-0391

inc/elementz.php in aliTalk 1.9.1.1 does not properly verify authentication, which allows remote attackers to add an arbitrary user account via a modified lilil parameter, in conjunction with the ubild and pa parameters.

CVSS2: 7.5
5%
Низкий
около 18 лет назад

Уязвимостей на страницу