Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 384 604

Количество 384 604

nvd логотип

CVE-2008-4650

почти 18 лет назад

SQL injection vulnerability in viewevent.php in myEvent 1.6 allows remote attackers to execute arbitrary SQL commands via the eventdate parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2008-4649

почти 18 лет назад

Session fixation vulnerability in Elxis CMS 2008.1 revision 2204 allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2008-4648

почти 18 лет назад

Cross-site scripting (XSS) vulnerability in index.php in Elxis CMS 2008.1 revision 2204 allows remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO or the (2) option, (3) Itemid, (4) id, (5) task, (6) bid, and (7) contact_id parameters. NOTE: the error might be located in modules/mod_language.php, and index.php might be the interaction point.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2008-4647

почти 18 лет назад

SQL injection vulnerability in index.php in sweetCMS 1.5.2 allows remote attackers to execute arbitrary SQL commands via the page parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2008-4646

почти 18 лет назад

The Websense Reporter Module in Websense Enterprise 6.3.2 stores the SQL database system administrator password in plaintext in CreateDbInstall.log, which allows local users to gain privileges to the database.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2008-4645

почти 18 лет назад

plugins/event_tracer/event_list.php in PhpWebGallery 1.7.2 and earlier allows remote authenticated administrators to execute arbitrary PHP code via PHP sequences in the sort parameter, which is processed by create_function.

CVSS2: 9
EPSS: Низкий
nvd логотип

CVE-2008-4644

почти 18 лет назад

hits.php in myWebland myStats allows remote attackers to bypass IP address restrictions via a modified X-Forwarded-For HTTP header.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2008-4643

почти 18 лет назад

SQL injection vulnerability in hits.php in myWebland myStats allows remote attackers to execute arbitrary SQL commands via the sortby parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2008-4642

почти 18 лет назад

SQL injection vulnerability in profile.php in AstroSPACES 1.1.1 allows remote attackers to execute arbitrary SQL commands via the id parameter in a view action.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2008-4641

почти 18 лет назад

The DoCommand function in jhead.c in Matthias Wandel jhead 2.84 and earlier allows attackers to execute arbitrary commands via shell metacharacters in unspecified input.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2008-4640

почти 18 лет назад

The DoCommand function in jhead.c in Matthias Wandel jhead 2.84 and earlier allows local users to delete arbitrary files via vectors involving a modified input filename in which (1) a final "z" character is replaced by a "t" character or (2) a final "t" character is replaced by a "z" character.

CVSS2: 3.6
EPSS: Низкий
nvd логотип

CVE-2008-4639

почти 18 лет назад

jhead.c in Matthias Wandel jhead 2.84 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2008-4638

почти 18 лет назад

qioadmin in the Quick I/O for Database feature in Symantec Veritas File System (VxFS) on HP-UX, and before 5.0 MP3 on Solaris, Linux, and AIX, allows local users to read arbitrary files by causing qioadmin to write a file's content to standard error in an error message.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2008-4637

почти 18 лет назад

Cross-site scripting (XSS) vulnerability in cpCommerce before 1.2.4 allows remote attackers to inject arbitrary web script or HTML via unknown vectors in the advanced search feature. NOTE: this is probably a variant of CVE-2008-4121.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2008-4636

почти 18 лет назад

yast2-backup 2.14.2 through 2.16.6 on SUSE Linux and Novell Linux allows local users to gain privileges via shell metacharacters in filenames used by the backup process.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2008-4635

почти 18 лет назад

Unspecified vulnerability in Hisanaga Electric Co, Ltd. hisa_cart 1.29 and earlier, a module for XOOPS, allows remote attackers to obtain sensitive user information via unknown vectors.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2008-4634

почти 18 лет назад

Cross-site scripting (XSS) vulnerability in Movable Type 4 through 4.21 allows remote attackers to inject arbitrary web script or HTML via unknown vectors related to the administrative page, a different vulnerability than CVE-2008-4079.

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2008-4633

почти 18 лет назад

SQL injection vulnerability in Node Vote 5.x before 5.x-1.1 and 6.x before 6.x-1.0, a module for Drupal, when "Allow user to vote again" is enabled, allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors related to a "previously cast vote."

CVSS2: 6
EPSS: Низкий
nvd логотип

CVE-2008-4632

почти 18 лет назад

Multiple directory traversal vulnerabilities in index.php in Kure 0.6.3, when magic_quotes_gpc is disabled, allow remote attackers to read and possibly execute arbitrary local files via a .. (dot dot) in the (1) post and (2) doc parameters.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2008-4631

почти 18 лет назад

Stack-based buffer overflow in the Message::AddToString function in message/Message.cpp in MUSCLE before 4.40 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted message. NOTE: some of these details are obtained from third party information.

CVSS2: 10
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2008-4650

SQL injection vulnerability in viewevent.php in myEvent 1.6 allows remote attackers to execute arbitrary SQL commands via the eventdate parameter.

CVSS2: 7.5
1%
Низкий
почти 18 лет назад
nvd логотип
CVE-2008-4649

Session fixation vulnerability in Elxis CMS 2008.1 revision 2204 allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.

CVSS2: 7.5
2%
Низкий
почти 18 лет назад
nvd логотип
CVE-2008-4648

Cross-site scripting (XSS) vulnerability in index.php in Elxis CMS 2008.1 revision 2204 allows remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO or the (2) option, (3) Itemid, (4) id, (5) task, (6) bid, and (7) contact_id parameters. NOTE: the error might be located in modules/mod_language.php, and index.php might be the interaction point.

CVSS2: 4.3
1%
Низкий
почти 18 лет назад
nvd логотип
CVE-2008-4647

SQL injection vulnerability in index.php in sweetCMS 1.5.2 allows remote attackers to execute arbitrary SQL commands via the page parameter.

CVSS2: 7.5
1%
Низкий
почти 18 лет назад
nvd логотип
CVE-2008-4646

The Websense Reporter Module in Websense Enterprise 6.3.2 stores the SQL database system administrator password in plaintext in CreateDbInstall.log, which allows local users to gain privileges to the database.

CVSS2: 2.1
0%
Низкий
почти 18 лет назад
nvd логотип
CVE-2008-4645

plugins/event_tracer/event_list.php in PhpWebGallery 1.7.2 and earlier allows remote authenticated administrators to execute arbitrary PHP code via PHP sequences in the sort parameter, which is processed by create_function.

CVSS2: 9
7%
Низкий
почти 18 лет назад
nvd логотип
CVE-2008-4644

hits.php in myWebland myStats allows remote attackers to bypass IP address restrictions via a modified X-Forwarded-For HTTP header.

CVSS2: 7.5
3%
Низкий
почти 18 лет назад
nvd логотип
CVE-2008-4643

SQL injection vulnerability in hits.php in myWebland myStats allows remote attackers to execute arbitrary SQL commands via the sortby parameter.

CVSS2: 7.5
1%
Низкий
почти 18 лет назад
nvd логотип
CVE-2008-4642

SQL injection vulnerability in profile.php in AstroSPACES 1.1.1 allows remote attackers to execute arbitrary SQL commands via the id parameter in a view action.

CVSS2: 7.5
1%
Низкий
почти 18 лет назад
nvd логотип
CVE-2008-4641

The DoCommand function in jhead.c in Matthias Wandel jhead 2.84 and earlier allows attackers to execute arbitrary commands via shell metacharacters in unspecified input.

CVSS2: 10
2%
Низкий
почти 18 лет назад
nvd логотип
CVE-2008-4640

The DoCommand function in jhead.c in Matthias Wandel jhead 2.84 and earlier allows local users to delete arbitrary files via vectors involving a modified input filename in which (1) a final "z" character is replaced by a "t" character or (2) a final "t" character is replaced by a "z" character.

CVSS2: 3.6
0%
Низкий
почти 18 лет назад
nvd логотип
CVE-2008-4639

jhead.c in Matthias Wandel jhead 2.84 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file.

CVSS2: 4.6
0%
Низкий
почти 18 лет назад
nvd логотип
CVE-2008-4638

qioadmin in the Quick I/O for Database feature in Symantec Veritas File System (VxFS) on HP-UX, and before 5.0 MP3 on Solaris, Linux, and AIX, allows local users to read arbitrary files by causing qioadmin to write a file's content to standard error in an error message.

CVSS2: 4.6
0%
Низкий
почти 18 лет назад
nvd логотип
CVE-2008-4637

Cross-site scripting (XSS) vulnerability in cpCommerce before 1.2.4 allows remote attackers to inject arbitrary web script or HTML via unknown vectors in the advanced search feature. NOTE: this is probably a variant of CVE-2008-4121.

CVSS2: 4.3
1%
Низкий
почти 18 лет назад
nvd логотип
CVE-2008-4636

yast2-backup 2.14.2 through 2.16.6 on SUSE Linux and Novell Linux allows local users to gain privileges via shell metacharacters in filenames used by the backup process.

CVSS2: 7.2
0%
Низкий
почти 18 лет назад
nvd логотип
CVE-2008-4635

Unspecified vulnerability in Hisanaga Electric Co, Ltd. hisa_cart 1.29 and earlier, a module for XOOPS, allows remote attackers to obtain sensitive user information via unknown vectors.

CVSS2: 5
1%
Низкий
почти 18 лет назад
nvd логотип
CVE-2008-4634

Cross-site scripting (XSS) vulnerability in Movable Type 4 through 4.21 allows remote attackers to inject arbitrary web script or HTML via unknown vectors related to the administrative page, a different vulnerability than CVE-2008-4079.

CVSS2: 3.5
1%
Низкий
почти 18 лет назад
nvd логотип
CVE-2008-4633

SQL injection vulnerability in Node Vote 5.x before 5.x-1.1 and 6.x before 6.x-1.0, a module for Drupal, when "Allow user to vote again" is enabled, allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors related to a "previously cast vote."

CVSS2: 6
1%
Низкий
почти 18 лет назад
nvd логотип
CVE-2008-4632

Multiple directory traversal vulnerabilities in index.php in Kure 0.6.3, when magic_quotes_gpc is disabled, allow remote attackers to read and possibly execute arbitrary local files via a .. (dot dot) in the (1) post and (2) doc parameters.

CVSS2: 6.8
2%
Низкий
почти 18 лет назад
nvd логотип
CVE-2008-4631

Stack-based buffer overflow in the Message::AddToString function in message/Message.cpp in MUSCLE before 4.40 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted message. NOTE: some of these details are obtained from third party information.

CVSS2: 10
5%
Низкий
почти 18 лет назад

Уязвимостей на страницу