Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 384 604

Количество 384 604

nvd логотип

CVE-2008-5132

почти 18 лет назад

SQL injection vulnerability in inc/ajax/ajax_rating.php in MemHT Portal 4.0.1 allows remote attackers to execute arbitrary SQL commands via the X-Forwarded-For HTTP header.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2008-5131

почти 18 лет назад

Multiple SQL injection vulnerabilities in Develop It Easy News And Article System 1.4 allow remote attackers to execute arbitrary SQL commands via (1) the aid parameter to article_details.php, and the (2) username and (3) password to the admin panel (admin/index.php).

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2008-5130

почти 18 лет назад

Ocean12 Calendar Manager Gold 2.04 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to o12cal.mdb.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2008-5129

почти 18 лет назад

Ocean12 Poll Manager Pro 1.00 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to o12poll.mdb.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2008-5128

почти 18 лет назад

Ocean12 Membership Manager Pro stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to o12member.mdb.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2008-5127

почти 18 лет назад

Ocean12 Contact Manager Pro 1.02 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to o12con.mdb.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2008-5126

почти 18 лет назад

Cross-site scripting (XSS) vulnerability in search.php in BoutikOne CMS allows remote attackers to inject arbitrary web script or HTML via the search_query parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2008-5125

почти 18 лет назад

admin.php in CCleague Pro 1.2 allows remote attackers to bypass authentication by setting the type cookie value to admin.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2008-5124

почти 18 лет назад

JSCAPE Secure FTP Applet 4.8.0 and earlier does not ask the user to verify a new or mismatched SSH host key, which makes it easier for remote attackers to perform man-in-the-middle attacks.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2008-5123

почти 18 лет назад

SQL injection vulnerability in admin.php in CCleague Pro 1.2 allows remote attackers to execute arbitrary SQL commands via the u parameter.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2008-5122

почти 18 лет назад

SQL injection vulnerability in WorkArea/ContentRatingGraph.aspx in Ektron CMS400.NET 7.5.2 and earlier allows remote attackers to execute arbitrary SQL commands via the res parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2008-5121

почти 18 лет назад

dne2000.sys in Citrix Deterministic Network Enhancer (DNE) 2.21.7.233 through 3.21.7.17464, as used in (1) Cisco VPN Client, (2) Blue Coat WinProxy, and (3) SafeNet SoftRemote and HighAssurance Remote, allows local users to gain privileges via a crafted DNE_IOCTL DeviceIoControl request to the \\.\DNE device interface.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2008-5120

почти 18 лет назад

Stack-based buffer overflow in the Process Software MultiNet finger service (aka FINGERD) for HP OpenVMS 8.3 allows remote attackers to execute arbitrary code via a long request string.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2008-5119

почти 18 лет назад

Cross-site scripting (XSS) vulnerability in search.php in Scripts4Profit DXShopCart 4.30mc allows remote attackers to inject arbitrary web script or HTML via the keyword parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2008-5118

почти 18 лет назад

Sun Java System Identity Manager 6.0 through 6.0 SP4, 7.0, and 7.1 allows remote attackers to inject frames from arbitrary web sites and conduct phishing attacks via unspecified vectors, related to "frame injection."

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2008-5117

почти 18 лет назад

Open redirect vulnerability in Sun Java System Identity Manager 6.0 through 6.0 SP4, 7.0, and 7.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2008-5116

почти 18 лет назад

Directory traversal vulnerability in idm/includes/helpServer.jsp in Sun Java System Identity Manager 6.0 through 6.0 SP4, 7.0, and 7.1 allows remote attackers to read arbitrary files in the filesystem of the IDM server via directory traversal sequences in the ext parameter.

CVSS2: 7.8
EPSS: Низкий
nvd логотип

CVE-2008-5115

почти 18 лет назад

Cross-site request forgery (CSRF) vulnerability in Sun Java System Identity Manager 6.0 through 6.0 SP4, 7.0, and 7.1 allows remote attackers to hijack the authentication of administrators for requests that update the password via idm/admin/changeself.jsp.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2008-5114

почти 18 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager 6.0 through 6.0 SP4, 7.0, and 7.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2008-5113

почти 18 лет назад

WordPress 2.6.3 relies on the REQUEST superglobal array in certain dangerous situations, which makes it easier for remote attackers to conduct delayed and persistent cross-site request forgery (CSRF) attacks via crafted cookies, as demonstrated by attacks that (1) delete user accounts or (2) cause a denial of service (loss of application access). NOTE: this issue relies on the presence of an independent vulnerability that allows cookie injection.

CVSS2: 4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2008-5132

SQL injection vulnerability in inc/ajax/ajax_rating.php in MemHT Portal 4.0.1 allows remote attackers to execute arbitrary SQL commands via the X-Forwarded-For HTTP header.

CVSS2: 7.5
2%
Низкий
почти 18 лет назад
nvd логотип
CVE-2008-5131

Multiple SQL injection vulnerabilities in Develop It Easy News And Article System 1.4 allow remote attackers to execute arbitrary SQL commands via (1) the aid parameter to article_details.php, and the (2) username and (3) password to the admin panel (admin/index.php).

CVSS2: 7.5
1%
Низкий
почти 18 лет назад
nvd логотип
CVE-2008-5130

Ocean12 Calendar Manager Gold 2.04 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to o12cal.mdb.

CVSS2: 5
1%
Низкий
почти 18 лет назад
nvd логотип
CVE-2008-5129

Ocean12 Poll Manager Pro 1.00 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to o12poll.mdb.

CVSS2: 5
1%
Низкий
почти 18 лет назад
nvd логотип
CVE-2008-5128

Ocean12 Membership Manager Pro stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to o12member.mdb.

CVSS2: 5
1%
Низкий
почти 18 лет назад
nvd логотип
CVE-2008-5127

Ocean12 Contact Manager Pro 1.02 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to o12con.mdb.

CVSS2: 5
1%
Низкий
почти 18 лет назад
nvd логотип
CVE-2008-5126

Cross-site scripting (XSS) vulnerability in search.php in BoutikOne CMS allows remote attackers to inject arbitrary web script or HTML via the search_query parameter.

CVSS2: 4.3
1%
Низкий
почти 18 лет назад
nvd логотип
CVE-2008-5125

admin.php in CCleague Pro 1.2 allows remote attackers to bypass authentication by setting the type cookie value to admin.

CVSS2: 6.8
2%
Низкий
почти 18 лет назад
nvd логотип
CVE-2008-5124

JSCAPE Secure FTP Applet 4.8.0 and earlier does not ask the user to verify a new or mismatched SSH host key, which makes it easier for remote attackers to perform man-in-the-middle attacks.

CVSS2: 7.5
2%
Низкий
почти 18 лет назад
nvd логотип
CVE-2008-5123

SQL injection vulnerability in admin.php in CCleague Pro 1.2 allows remote attackers to execute arbitrary SQL commands via the u parameter.

CVSS2: 6.8
1%
Низкий
почти 18 лет назад
nvd логотип
CVE-2008-5122

SQL injection vulnerability in WorkArea/ContentRatingGraph.aspx in Ektron CMS400.NET 7.5.2 and earlier allows remote attackers to execute arbitrary SQL commands via the res parameter.

CVSS2: 7.5
1%
Низкий
почти 18 лет назад
nvd логотип
CVE-2008-5121

dne2000.sys in Citrix Deterministic Network Enhancer (DNE) 2.21.7.233 through 3.21.7.17464, as used in (1) Cisco VPN Client, (2) Blue Coat WinProxy, and (3) SafeNet SoftRemote and HighAssurance Remote, allows local users to gain privileges via a crafted DNE_IOCTL DeviceIoControl request to the \\.\DNE device interface.

CVSS2: 7.2
1%
Низкий
почти 18 лет назад
nvd логотип
CVE-2008-5120

Stack-based buffer overflow in the Process Software MultiNet finger service (aka FINGERD) for HP OpenVMS 8.3 allows remote attackers to execute arbitrary code via a long request string.

CVSS2: 10
10%
Низкий
почти 18 лет назад
nvd логотип
CVE-2008-5119

Cross-site scripting (XSS) vulnerability in search.php in Scripts4Profit DXShopCart 4.30mc allows remote attackers to inject arbitrary web script or HTML via the keyword parameter.

CVSS2: 4.3
1%
Низкий
почти 18 лет назад
nvd логотип
CVE-2008-5118

Sun Java System Identity Manager 6.0 through 6.0 SP4, 7.0, and 7.1 allows remote attackers to inject frames from arbitrary web sites and conduct phishing attacks via unspecified vectors, related to "frame injection."

CVSS2: 4.3
2%
Низкий
почти 18 лет назад
nvd логотип
CVE-2008-5117

Open redirect vulnerability in Sun Java System Identity Manager 6.0 through 6.0 SP4, 7.0, and 7.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

CVSS2: 6.4
3%
Низкий
почти 18 лет назад
nvd логотип
CVE-2008-5116

Directory traversal vulnerability in idm/includes/helpServer.jsp in Sun Java System Identity Manager 6.0 through 6.0 SP4, 7.0, and 7.1 allows remote attackers to read arbitrary files in the filesystem of the IDM server via directory traversal sequences in the ext parameter.

CVSS2: 7.8
4%
Низкий
почти 18 лет назад
nvd логотип
CVE-2008-5115

Cross-site request forgery (CSRF) vulnerability in Sun Java System Identity Manager 6.0 through 6.0 SP4, 7.0, and 7.1 allows remote attackers to hijack the authentication of administrators for requests that update the password via idm/admin/changeself.jsp.

CVSS2: 6.8
3%
Низкий
почти 18 лет назад
nvd логотип
CVE-2008-5114

Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager 6.0 through 6.0 SP4, 7.0, and 7.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS2: 4.3
2%
Низкий
почти 18 лет назад
nvd логотип
CVE-2008-5113

WordPress 2.6.3 relies on the REQUEST superglobal array in certain dangerous situations, which makes it easier for remote attackers to conduct delayed and persistent cross-site request forgery (CSRF) attacks via crafted cookies, as demonstrated by attacks that (1) delete user accounts or (2) cause a denial of service (loss of application access). NOTE: this issue relies on the presence of an independent vulnerability that allows cookie injection.

CVSS2: 4
1%
Низкий
почти 18 лет назад

Уязвимостей на страницу