Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 384 542

Количество 384 542

nvd логотип

CVE-2008-4143

почти 18 лет назад

SQL injection vulnerability in category_search.php in RazorCommerce Shopping Cart allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2008-4142

почти 18 лет назад

SQL injection vulnerability in article.php in E-Php CMS allows remote attackers to execute arbitrary SQL commands via the es_id parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2008-4141

почти 18 лет назад

Multiple PHP remote file inclusion vulnerabilities in x10Media x10 Automatic MP3 Script 1.5.5 allow remote attackers to execute arbitrary PHP code via a URL in the web_root parameter to (1) includes/function_core.php and (2) templates/layout_lyrics.php.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2008-4140

почти 18 лет назад

Cross-site scripting (XSS) vulnerability in admin.php in Quick.Cart 3.1 allows remote attackers to inject arbitrary web script or HTML via the query string.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2008-4139

почти 18 лет назад

Cross-site scripting (XSS) vulnerability in admin.php in OpenSolution Quick.Cms.Lite 2.1 allows remote attackers to inject arbitrary web script or HTML via the query string.

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2008-4138

почти 18 лет назад

PHP remote file inclusion vulnerability in skin_shop/standard/3_plugin_twindow/twindow_notice.php in TECHNOTE 7 allows remote attackers to execute arbitrary PHP code via a URL in the shop_this_skin_path parameter.

CVSS2: 10
EPSS: Средний
nvd логотип

CVE-2008-4137

почти 18 лет назад

PHP remote file inclusion vulnerability in footer.php in PHP-Crawler 0.8 allows remote attackers to execute arbitrary PHP code via a URL in the footer_file parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2008-4136

почти 18 лет назад

Michael Roth Software Personal FTP Server (PFT) 6.0f allows remote attackers to cause a denial of service (service crash) via multiple RETR commands, possibly involving long filenames.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2008-4135

почти 18 лет назад

Symbian OS S60 3rd edition on the Nokia E90 Communicator 07.40.1.2 Ra-6 and Nseries N82 allows remote attackers to cause a denial of service (device crash) via multiple deauthentication (DeAuth) frames.

CVSS2: 7.8
EPSS: Низкий
nvd логотип

CVE-2008-4134

почти 18 лет назад

PHP remote file inclusion vulnerability in manager/static/view.php in phpRealty 0.03 and earlier, and possibly other versions before 0.05, allows remote attackers to execute arbitrary PHP code via a URL in the INC parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2008-4133

почти 18 лет назад

The web proxy service on the D-Link DIR-100 with firmware 1.12 and earlier does not properly filter web requests with large URLs, which allows remote attackers to bypass web restriction filters.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2008-4132

почти 18 лет назад

Stack-based buffer overflow in the VSFlexGrid.VSFlexGridL ActiveX control in ComponentOne VSFlexGrid 7.0.1.151 and 8.0.20072.239 allows remote attackers to execute arbitrary code via a long first argument to the Archive method. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

CVSS2: 9.3
EPSS: Низкий
nvd логотип

CVE-2008-4131

почти 18 лет назад

Multiple unspecified vulnerabilities in Sun Solaris 8 through 10 allow local users to gain privileges via vectors related to handling of tags with (1) the -t option and (2) the :tag command in the (a) vi, (b) ex, (c) vedit, (d) view, and (e) edit programs.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2008-4130

почти 18 лет назад

Cross-site scripting (XSS) vulnerability in Gallery 2.x before 2.2.6 allows remote attackers to inject arbitrary web script or HTML via a crafted Flash animation, related to the ability of the animation to "interact with the embedding page."

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2008-4129

почти 18 лет назад

Gallery before 1.5.9, and 2.x before 2.2.6, does not properly handle ZIP archives containing symbolic links, which allows remote authenticated users to conduct directory traversal attacks and read arbitrary files via vectors related to the archive upload (aka zip upload) functionality.

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2008-4128

почти 18 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12.4 on the 871 Integrated Services Router allow remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI, and (2) a certain "alias exec" command to the /level/15/exec/-/configure/http URI. NOTE: some of these details are obtained from third party information.

CVSS3: 4.3
EPSS: Средний
nvd логотип

CVE-2008-4127

почти 18 лет назад

Mshtml.dll in Microsoft Internet Explorer 7 Gold 7.0.5730 and 8 Beta 8.0.6001 on Windows XP SP2 allows remote attackers to cause a denial of service (failure of subsequent image rendering) via a crafted PNG file, related to an infinite loop in the CDwnTaskExec::ThreadExec function.

CVSS2: 4.3
EPSS: Средний
nvd логотип

CVE-2008-4126

почти 18 лет назад

PyDNS (aka python-dns) before 2.3.1-5 in Debian GNU/Linux does not use random source ports for DNS requests and does not use random transaction IDs for DNS retries, which makes it easier for remote attackers to spoof DNS responses, a different vulnerability than CVE-2008-1447. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4099.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2008-4125

почти 18 лет назад

The search function in phpBB 2.x provides a search_id value that leaks the state of PHP's PRNG, which allows remote attackers to obtain potentially sensitive information, as demonstrated by a cross-application attack against WordPress, a different vulnerability than CVE-2006-0632.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2008-4122

больше 17 лет назад

Joomla! 1.5.8 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2008-4143

SQL injection vulnerability in category_search.php in RazorCommerce Shopping Cart allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS2: 7.5
1%
Низкий
почти 18 лет назад
nvd логотип
CVE-2008-4142

SQL injection vulnerability in article.php in E-Php CMS allows remote attackers to execute arbitrary SQL commands via the es_id parameter.

CVSS2: 7.5
1%
Низкий
почти 18 лет назад
nvd логотип
CVE-2008-4141

Multiple PHP remote file inclusion vulnerabilities in x10Media x10 Automatic MP3 Script 1.5.5 allow remote attackers to execute arbitrary PHP code via a URL in the web_root parameter to (1) includes/function_core.php and (2) templates/layout_lyrics.php.

CVSS2: 7.5
3%
Низкий
почти 18 лет назад
nvd логотип
CVE-2008-4140

Cross-site scripting (XSS) vulnerability in admin.php in Quick.Cart 3.1 allows remote attackers to inject arbitrary web script or HTML via the query string.

CVSS2: 4.3
1%
Низкий
почти 18 лет назад
nvd логотип
CVE-2008-4139

Cross-site scripting (XSS) vulnerability in admin.php in OpenSolution Quick.Cms.Lite 2.1 allows remote attackers to inject arbitrary web script or HTML via the query string.

CVSS2: 2.6
2%
Низкий
почти 18 лет назад
nvd логотип
CVE-2008-4138

PHP remote file inclusion vulnerability in skin_shop/standard/3_plugin_twindow/twindow_notice.php in TECHNOTE 7 allows remote attackers to execute arbitrary PHP code via a URL in the shop_this_skin_path parameter.

CVSS2: 10
10%
Средний
почти 18 лет назад
nvd логотип
CVE-2008-4137

PHP remote file inclusion vulnerability in footer.php in PHP-Crawler 0.8 allows remote attackers to execute arbitrary PHP code via a URL in the footer_file parameter.

CVSS2: 7.5
2%
Низкий
почти 18 лет назад
nvd логотип
CVE-2008-4136

Michael Roth Software Personal FTP Server (PFT) 6.0f allows remote attackers to cause a denial of service (service crash) via multiple RETR commands, possibly involving long filenames.

CVSS2: 5
3%
Низкий
почти 18 лет назад
nvd логотип
CVE-2008-4135

Symbian OS S60 3rd edition on the Nokia E90 Communicator 07.40.1.2 Ra-6 and Nseries N82 allows remote attackers to cause a denial of service (device crash) via multiple deauthentication (DeAuth) frames.

CVSS2: 7.8
4%
Низкий
почти 18 лет назад
nvd логотип
CVE-2008-4134

PHP remote file inclusion vulnerability in manager/static/view.php in phpRealty 0.03 and earlier, and possibly other versions before 0.05, allows remote attackers to execute arbitrary PHP code via a URL in the INC parameter.

CVSS2: 7.5
8%
Низкий
почти 18 лет назад
nvd логотип
CVE-2008-4133

The web proxy service on the D-Link DIR-100 with firmware 1.12 and earlier does not properly filter web requests with large URLs, which allows remote attackers to bypass web restriction filters.

CVSS2: 4.3
4%
Низкий
почти 18 лет назад
nvd логотип
CVE-2008-4132

Stack-based buffer overflow in the VSFlexGrid.VSFlexGridL ActiveX control in ComponentOne VSFlexGrid 7.0.1.151 and 8.0.20072.239 allows remote attackers to execute arbitrary code via a long first argument to the Archive method. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

CVSS2: 9.3
4%
Низкий
почти 18 лет назад
nvd логотип
CVE-2008-4131

Multiple unspecified vulnerabilities in Sun Solaris 8 through 10 allow local users to gain privileges via vectors related to handling of tags with (1) the -t option and (2) the :tag command in the (a) vi, (b) ex, (c) vedit, (d) view, and (e) edit programs.

CVSS2: 7.2
1%
Низкий
почти 18 лет назад
nvd логотип
CVE-2008-4130

Cross-site scripting (XSS) vulnerability in Gallery 2.x before 2.2.6 allows remote attackers to inject arbitrary web script or HTML via a crafted Flash animation, related to the ability of the animation to "interact with the embedding page."

CVSS2: 4.3
2%
Низкий
почти 18 лет назад
nvd логотип
CVE-2008-4129

Gallery before 1.5.9, and 2.x before 2.2.6, does not properly handle ZIP archives containing symbolic links, which allows remote authenticated users to conduct directory traversal attacks and read arbitrary files via vectors related to the archive upload (aka zip upload) functionality.

CVSS2: 4
2%
Низкий
почти 18 лет назад
nvd логотип
CVE-2008-4128

Multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12.4 on the 871 Integrated Services Router allow remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI, and (2) a certain "alias exec" command to the /level/15/exec/-/configure/http URI. NOTE: some of these details are obtained from third party information.

CVSS3: 4.3
34%
Средний
почти 18 лет назад
nvd логотип
CVE-2008-4127

Mshtml.dll in Microsoft Internet Explorer 7 Gold 7.0.5730 and 8 Beta 8.0.6001 on Windows XP SP2 allows remote attackers to cause a denial of service (failure of subsequent image rendering) via a crafted PNG file, related to an infinite loop in the CDwnTaskExec::ThreadExec function.

CVSS2: 4.3
16%
Средний
почти 18 лет назад
nvd логотип
CVE-2008-4126

PyDNS (aka python-dns) before 2.3.1-5 in Debian GNU/Linux does not use random source ports for DNS requests and does not use random transaction IDs for DNS retries, which makes it easier for remote attackers to spoof DNS responses, a different vulnerability than CVE-2008-1447. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4099.

CVSS2: 6.4
2%
Низкий
почти 18 лет назад
nvd логотип
CVE-2008-4125

The search function in phpBB 2.x provides a search_id value that leaks the state of PHP's PRNG, which allows remote attackers to obtain potentially sensitive information, as demonstrated by a cross-application attack against WordPress, a different vulnerability than CVE-2006-0632.

CVSS2: 5
2%
Низкий
почти 18 лет назад
nvd логотип
CVE-2008-4122

Joomla! 1.5.8 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

CVSS3: 7.5
1%
Низкий
больше 17 лет назад

Уязвимостей на страницу