Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 384 258

Количество 384 258

nvd логотип

CVE-2008-3510

около 18 лет назад

Cross-site scripting (XSS) vulnerability in livehelp_js.php in Crafty Syntax Live Help (CSLH) 2.14.6 allows remote attackers to inject arbitrary web script or HTML via the department parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2008-3509

около 18 лет назад

LoveCMS 1.6.2 does not require administrative authentication for (1) addblock.php, (2) blocks.php, and (3) themes.php in system/admin/, which allows remote attackers to change the configuration or execute arbitrary PHP code via addition of blocks, and other vectors.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2008-3508

около 18 лет назад

LiteNews 0.1 (aka 01), and possibly 1.2 and earlier, allows remote attackers to bypass authentication and gain administrative access by setting the admin cookie.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2008-3507

около 18 лет назад

SQL injection vulnerability in index.php in LiteNews 0.1 (aka 01), and possibly 1.2 and earlier, allows remote attackers to execute arbitrary SQL commands via the id parameter in a view action.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2008-3506

около 18 лет назад

SQL injection vulnerability in PolyPager 1.0 rc2 and earlier allows remote attackers to execute arbitrary SQL commands via the nr parameter to the default URI.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2008-3505

около 18 лет назад

Cross-site scripting (XSS) vulnerability in PolyPager 1.0 rc2 and earlier allows remote attackers to inject arbitrary web script or HTML via the nr parameter to the default URI.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2008-3504

около 18 лет назад

Unspecified vulnerability in mask PHP File Manager (mPFM) before 2.3 has unknown impact and remote attack vectors related to "manipulation of cookies."

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2008-3503

около 18 лет назад

RSSFromParent in Plain Black WebGUI before 7.5.13 does not restrict view access to Collaboration System (CS) RSS feeds, which allows remote attackers to obtain sensitive information (CS data).

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2008-3502

около 18 лет назад

Unspecified vulnerability in Best Practical Solutions RT 3.0.0 through 3.6.6 allows remote authenticated users to cause a denial of service (CPU or memory consumption) via unspecified vectors related to the Devel::StackTrace module for Perl.

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2008-3501

около 18 лет назад

Cross-site scripting (XSS) vulnerability in the WebAccess simple interface in Novell Groupwise 7.0.x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2008-3500

около 18 лет назад

Cross-site scripting (XSS) vulnerability in the Suggested Terms module 5.x before 5.x-1.2 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via crafted Taxonomy terms.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2008-3499

около 18 лет назад

Unspecified vulnerability in "a page in the workarea folder" in Ektron CMS400.NET 7.00 through 7.04 and 7.50 through 7.52 has unknown impact and attack vectors.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2008-3498

около 18 лет назад

SQL injection vulnerability in the nBill (com_netinvoice) component 1.2.0 SP1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid parameter in an orders action to index.php. NOTE: some of these details are obtained from third party information.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2008-3497

около 18 лет назад

SQL injection vulnerability in pages.php in MyPHP CMS 0.3.1 allows remote attackers to execute arbitrary SQL commands via the pid parameter.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2008-3496

около 18 лет назад

Buffer overflow in format descriptor parsing in the uvc_parse_format function in drivers/media/video/uvc/uvc_driver.c in uvcvideo in the video4linux (V4L) implementation in the Linux kernel before 2.6.26.1 has unknown impact and attack vectors.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2008-3495

около 18 лет назад

SQL injection vulnerability in kategori.asp in Pcshey Portal allows remote attackers to execute arbitrary SQL commands via the kid parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2008-3494

около 18 лет назад

8e6 R3000 Internet Filter 2.0.12.10 allows remote attackers to bypass intended restrictions via an extra HTTP Host header with additional leading text placed before the real Host header.

CVSS2: 7.8
EPSS: Низкий
nvd логотип

CVE-2008-3493

около 18 лет назад

vncviewer.exe in RealVNC Windows Client 4.1.2.0 allows remote VNC servers to cause a denial of service (application crash) via a crafted frame buffer update packet.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2008-3492

около 18 лет назад

America's Army (aka AA or Army Game Project) 2.8.3.1 and earlier allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted UDP packet, probably involving a VoiceIndex value that is outside of the range specified by VOICE_MAX_CHATTERS.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2008-3491

около 18 лет назад

SQL injection vulnerability in go.php in Scripts24 iPost 1.0.1 and iTGP 1.0.4 allows remote attackers to execute arbitrary SQL commands via the id parameter in a report action.

CVSS2: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2008-3510

Cross-site scripting (XSS) vulnerability in livehelp_js.php in Crafty Syntax Live Help (CSLH) 2.14.6 allows remote attackers to inject arbitrary web script or HTML via the department parameter.

CVSS2: 4.3
1%
Низкий
около 18 лет назад
nvd логотип
CVE-2008-3509

LoveCMS 1.6.2 does not require administrative authentication for (1) addblock.php, (2) blocks.php, and (3) themes.php in system/admin/, which allows remote attackers to change the configuration or execute arbitrary PHP code via addition of blocks, and other vectors.

CVSS2: 7.5
3%
Низкий
около 18 лет назад
nvd логотип
CVE-2008-3508

LiteNews 0.1 (aka 01), and possibly 1.2 and earlier, allows remote attackers to bypass authentication and gain administrative access by setting the admin cookie.

CVSS2: 5
3%
Низкий
около 18 лет назад
nvd логотип
CVE-2008-3507

SQL injection vulnerability in index.php in LiteNews 0.1 (aka 01), and possibly 1.2 and earlier, allows remote attackers to execute arbitrary SQL commands via the id parameter in a view action.

CVSS2: 7.5
1%
Низкий
около 18 лет назад
nvd логотип
CVE-2008-3506

SQL injection vulnerability in PolyPager 1.0 rc2 and earlier allows remote attackers to execute arbitrary SQL commands via the nr parameter to the default URI.

CVSS2: 7.5
1%
Низкий
около 18 лет назад
nvd логотип
CVE-2008-3505

Cross-site scripting (XSS) vulnerability in PolyPager 1.0 rc2 and earlier allows remote attackers to inject arbitrary web script or HTML via the nr parameter to the default URI.

CVSS2: 4.3
2%
Низкий
около 18 лет назад
nvd логотип
CVE-2008-3504

Unspecified vulnerability in mask PHP File Manager (mPFM) before 2.3 has unknown impact and remote attack vectors related to "manipulation of cookies."

CVSS2: 7.5
1%
Низкий
около 18 лет назад
nvd логотип
CVE-2008-3503

RSSFromParent in Plain Black WebGUI before 7.5.13 does not restrict view access to Collaboration System (CS) RSS feeds, which allows remote attackers to obtain sensitive information (CS data).

CVSS2: 5
2%
Низкий
около 18 лет назад
nvd логотип
CVE-2008-3502

Unspecified vulnerability in Best Practical Solutions RT 3.0.0 through 3.6.6 allows remote authenticated users to cause a denial of service (CPU or memory consumption) via unspecified vectors related to the Devel::StackTrace module for Perl.

CVSS2: 4
1%
Низкий
около 18 лет назад
nvd логотип
CVE-2008-3501

Cross-site scripting (XSS) vulnerability in the WebAccess simple interface in Novell Groupwise 7.0.x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS2: 4.3
1%
Низкий
около 18 лет назад
nvd логотип
CVE-2008-3500

Cross-site scripting (XSS) vulnerability in the Suggested Terms module 5.x before 5.x-1.2 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via crafted Taxonomy terms.

CVSS2: 4.3
1%
Низкий
около 18 лет назад
nvd логотип
CVE-2008-3499

Unspecified vulnerability in "a page in the workarea folder" in Ektron CMS400.NET 7.00 through 7.04 and 7.50 through 7.52 has unknown impact and attack vectors.

CVSS2: 10
1%
Низкий
около 18 лет назад
nvd логотип
CVE-2008-3498

SQL injection vulnerability in the nBill (com_netinvoice) component 1.2.0 SP1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid parameter in an orders action to index.php. NOTE: some of these details are obtained from third party information.

CVSS2: 7.5
2%
Низкий
около 18 лет назад
nvd логотип
CVE-2008-3497

SQL injection vulnerability in pages.php in MyPHP CMS 0.3.1 allows remote attackers to execute arbitrary SQL commands via the pid parameter.

CVSS2: 6.8
1%
Низкий
около 18 лет назад
nvd логотип
CVE-2008-3496

Buffer overflow in format descriptor parsing in the uvc_parse_format function in drivers/media/video/uvc/uvc_driver.c in uvcvideo in the video4linux (V4L) implementation in the Linux kernel before 2.6.26.1 has unknown impact and attack vectors.

CVSS2: 10
3%
Низкий
около 18 лет назад
nvd логотип
CVE-2008-3495

SQL injection vulnerability in kategori.asp in Pcshey Portal allows remote attackers to execute arbitrary SQL commands via the kid parameter.

CVSS2: 7.5
1%
Низкий
около 18 лет назад
nvd логотип
CVE-2008-3494

8e6 R3000 Internet Filter 2.0.12.10 allows remote attackers to bypass intended restrictions via an extra HTTP Host header with additional leading text placed before the real Host header.

CVSS2: 7.8
3%
Низкий
около 18 лет назад
nvd логотип
CVE-2008-3493

vncviewer.exe in RealVNC Windows Client 4.1.2.0 allows remote VNC servers to cause a denial of service (application crash) via a crafted frame buffer update packet.

CVSS2: 5
6%
Низкий
около 18 лет назад
nvd логотип
CVE-2008-3492

America's Army (aka AA or Army Game Project) 2.8.3.1 and earlier allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted UDP packet, probably involving a VoiceIndex value that is outside of the range specified by VOICE_MAX_CHATTERS.

CVSS2: 5
2%
Низкий
около 18 лет назад
nvd логотип
CVE-2008-3491

SQL injection vulnerability in go.php in Scripts24 iPost 1.0.1 and iTGP 1.0.4 allows remote attackers to execute arbitrary SQL commands via the id parameter in a report action.

CVSS2: 7.5
2%
Низкий
около 18 лет назад

Уязвимостей на страницу