Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 383 548

Количество 383 548

nvd логотип

CVE-2008-2565

около 18 лет назад

Multiple SQL injection vulnerabilities in PHP Address Book 3.1.5 and earlier allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) view.php and (2) edit.php. NOTE: it was later reported that 4.0.x is also affected.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2008-2564

около 18 лет назад

SQL injection vulnerability in the JotLoader (com_jotloader) component 1.2.1.a and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid parameter to index.php.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2008-2563

около 18 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in (1) dsp_main.php and (2) dsp_task_editor.php in SamTodo 1.1 allow remote attackers to inject arbitrary web script or HTML via the (a) tid parameter in a main.taskeditor edit action, and the (b) completed parameter in a main.default action, to index.php.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2008-2562

около 18 лет назад

SQL injection vulnerability in edCss.php in PowerPhlogger 2.2.5 and earlier allows remote authenticated users to execute arbitrary SQL commands via the css_str parameter in an edit action.

CVSS2: 6.5
EPSS: Низкий
nvd логотип

CVE-2008-2561

около 18 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in 427BB 2.3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO to (a) register.php, (b) reminder.php, and (c) search.php; the (2) uname, (3) email, and (4) email2 parameters to register.php; the (5) email parameter to reminder.php; and the (6) keywords parameter to search.php.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2008-2560

около 18 лет назад

SQL injection vulnerability in showpost.php in 427BB 2.3.1 allows remote attackers to execute arbitrary SQL commands via the post parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2008-2559

около 18 лет назад

Integer overflow in Borland Interbase 2007 SP2 (8.1.0.256) allows remote attackers to execute arbitrary code via a malformed packet to TCP port 3050, which triggers a stack-based buffer overflow. NOTE: this issue might be related to CVE-2008-0467.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2008-2558

около 18 лет назад

CRE Loaded 6.2.13.1 and earlier does not set the "Secure" attribute for cookies that are sent over HTTPS, which might allow remote attackers to sniff the cookies if they are sent over HTTP.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2008-2557

около 18 лет назад

Cross-site scripting (XSS) vulnerability in CRE Loaded 6.2.13.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) Links and (2) Links Submit pages.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2008-2556

около 18 лет назад

SQL injection vulnerability in read.php in PHP Visit Counter 0.4 and earlier allows remote attackers to execute arbitrary SQL commands via the datespan parameter in a read action.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2008-2555

около 18 лет назад

SQL injection vulnerability in index.php in EasyWay CMS allows remote attackers to execute arbitrary SQL commands via the mid parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2008-2554

около 18 лет назад

Multiple SQL injection vulnerabilities in BP Blog 6.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to template_permalink.asp and (2) cat parameter to template_archives_cat.asp.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2008-2553

около 18 лет назад

Cross-site scripting (XSS) vulnerability in Slashdot Like Automated Storytelling Homepage (Slash) (aka Slashcode) R_2_5_0_94 and earlier allows remote attackers to inject arbitrary web script or HTML via the userfield parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2008-2552

около 18 лет назад

Unspecified vulnerability in the Service Tag Registry on Sun Solaris 10, and Sun Service Tag before 1.1.3, allows local users to cause a denial of service (disk consumption) via unspecified vectors.

CVSS2: 4.9
EPSS: Низкий
nvd логотип

CVE-2008-2551

около 18 лет назад

The DownloaderActiveX Control (DownloaderActiveX.ocx) in Icona SpA C6 Messenger 1.0.0.1 allows remote attackers to force the download and execution of arbitrary files via a URL in the propDownloadUrl parameter with the propPostDownloadAction parameter set to "run."

CVSS2: 9.3
EPSS: Средний
nvd логотип

CVE-2008-2550

около 18 лет назад

Unspecified vulnerability in the Web Services Security component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.17 has unknown impact and attack vectors related to an attribute in the SOAP security header.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2008-2549

около 18 лет назад

Adobe Acrobat Reader 8.1.2 and earlier, and before 7.1.1, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a malformed PDF document, as demonstrated by 2008-HI2.pdf.

CVSS2: 4.3
EPSS: Средний
nvd логотип

CVE-2008-2548

около 18 лет назад

Stack-based buffer overflow in the JPEG thumbprint component in the EXIF parser on Motorola cell phones with RAZR firmware allows user-assisted remote attackers to execute arbitrary code via an MMS transmission of a malformed JPEG image, which triggers memory corruption.

CVSS2: 9.3
EPSS: Низкий
nvd логотип

CVE-2008-2547

около 18 лет назад

Stack-based buffer overflow in msiexec.exe 3.1.4000.1823 and 4.5.6001.22159 in Microsoft Windows Installer allows context-dependent attackers to execute arbitrary code via a long GUID value for the /x (aka /uninstall) option. NOTE: this issue might cross privilege boundaries if msiexec.exe is reachable via components such as ActiveX controls, and might additionally require a separate vulnerability in the control.

CVSS2: 9.3
EPSS: Низкий
nvd логотип

CVE-2008-2546

около 18 лет назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2008-1805. Reason: This candidate is a reservation duplicate of CVE-2008-1805. Notes: All CVE users should reference CVE-2008-1805 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2008-2565

Multiple SQL injection vulnerabilities in PHP Address Book 3.1.5 and earlier allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) view.php and (2) edit.php. NOTE: it was later reported that 4.0.x is also affected.

CVSS2: 7.5
2%
Низкий
около 18 лет назад
nvd логотип
CVE-2008-2564

SQL injection vulnerability in the JotLoader (com_jotloader) component 1.2.1.a and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid parameter to index.php.

CVSS2: 7.5
1%
Низкий
около 18 лет назад
nvd логотип
CVE-2008-2563

Multiple cross-site scripting (XSS) vulnerabilities in (1) dsp_main.php and (2) dsp_task_editor.php in SamTodo 1.1 allow remote attackers to inject arbitrary web script or HTML via the (a) tid parameter in a main.taskeditor edit action, and the (b) completed parameter in a main.default action, to index.php.

CVSS2: 4.3
1%
Низкий
около 18 лет назад
nvd логотип
CVE-2008-2562

SQL injection vulnerability in edCss.php in PowerPhlogger 2.2.5 and earlier allows remote authenticated users to execute arbitrary SQL commands via the css_str parameter in an edit action.

CVSS2: 6.5
1%
Низкий
около 18 лет назад
nvd логотип
CVE-2008-2561

Multiple cross-site scripting (XSS) vulnerabilities in 427BB 2.3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO to (a) register.php, (b) reminder.php, and (c) search.php; the (2) uname, (3) email, and (4) email2 parameters to register.php; the (5) email parameter to reminder.php; and the (6) keywords parameter to search.php.

CVSS2: 4.3
2%
Низкий
около 18 лет назад
nvd логотип
CVE-2008-2560

SQL injection vulnerability in showpost.php in 427BB 2.3.1 allows remote attackers to execute arbitrary SQL commands via the post parameter.

CVSS2: 7.5
1%
Низкий
около 18 лет назад
nvd логотип
CVE-2008-2559

Integer overflow in Borland Interbase 2007 SP2 (8.1.0.256) allows remote attackers to execute arbitrary code via a malformed packet to TCP port 3050, which triggers a stack-based buffer overflow. NOTE: this issue might be related to CVE-2008-0467.

CVSS2: 7.5
4%
Низкий
около 18 лет назад
nvd логотип
CVE-2008-2558

CRE Loaded 6.2.13.1 and earlier does not set the "Secure" attribute for cookies that are sent over HTTPS, which might allow remote attackers to sniff the cookies if they are sent over HTTP.

CVSS2: 5
1%
Низкий
около 18 лет назад
nvd логотип
CVE-2008-2557

Cross-site scripting (XSS) vulnerability in CRE Loaded 6.2.13.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) Links and (2) Links Submit pages.

CVSS2: 4.3
1%
Низкий
около 18 лет назад
nvd логотип
CVE-2008-2556

SQL injection vulnerability in read.php in PHP Visit Counter 0.4 and earlier allows remote attackers to execute arbitrary SQL commands via the datespan parameter in a read action.

CVSS2: 7.5
1%
Низкий
около 18 лет назад
nvd логотип
CVE-2008-2555

SQL injection vulnerability in index.php in EasyWay CMS allows remote attackers to execute arbitrary SQL commands via the mid parameter.

CVSS2: 7.5
1%
Низкий
около 18 лет назад
nvd логотип
CVE-2008-2554

Multiple SQL injection vulnerabilities in BP Blog 6.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to template_permalink.asp and (2) cat parameter to template_archives_cat.asp.

CVSS2: 7.5
1%
Низкий
около 18 лет назад
nvd логотип
CVE-2008-2553

Cross-site scripting (XSS) vulnerability in Slashdot Like Automated Storytelling Homepage (Slash) (aka Slashcode) R_2_5_0_94 and earlier allows remote attackers to inject arbitrary web script or HTML via the userfield parameter.

CVSS2: 4.3
2%
Низкий
около 18 лет назад
nvd логотип
CVE-2008-2552

Unspecified vulnerability in the Service Tag Registry on Sun Solaris 10, and Sun Service Tag before 1.1.3, allows local users to cause a denial of service (disk consumption) via unspecified vectors.

CVSS2: 4.9
0%
Низкий
около 18 лет назад
nvd логотип
CVE-2008-2551

The DownloaderActiveX Control (DownloaderActiveX.ocx) in Icona SpA C6 Messenger 1.0.0.1 allows remote attackers to force the download and execution of arbitrary files via a URL in the propDownloadUrl parameter with the propPostDownloadAction parameter set to "run."

CVSS2: 9.3
47%
Средний
около 18 лет назад
nvd логотип
CVE-2008-2550

Unspecified vulnerability in the Web Services Security component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.17 has unknown impact and attack vectors related to an attribute in the SOAP security header.

CVSS2: 5
2%
Низкий
около 18 лет назад
nvd логотип
CVE-2008-2549

Adobe Acrobat Reader 8.1.2 and earlier, and before 7.1.1, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a malformed PDF document, as demonstrated by 2008-HI2.pdf.

CVSS2: 4.3
53%
Средний
около 18 лет назад
nvd логотип
CVE-2008-2548

Stack-based buffer overflow in the JPEG thumbprint component in the EXIF parser on Motorola cell phones with RAZR firmware allows user-assisted remote attackers to execute arbitrary code via an MMS transmission of a malformed JPEG image, which triggers memory corruption.

CVSS2: 9.3
6%
Низкий
около 18 лет назад
nvd логотип
CVE-2008-2547

Stack-based buffer overflow in msiexec.exe 3.1.4000.1823 and 4.5.6001.22159 in Microsoft Windows Installer allows context-dependent attackers to execute arbitrary code via a long GUID value for the /x (aka /uninstall) option. NOTE: this issue might cross privilege boundaries if msiexec.exe is reachable via components such as ActiveX controls, and might additionally require a separate vulnerability in the control.

CVSS2: 9.3
8%
Низкий
около 18 лет назад
nvd логотип
CVE-2008-2546

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2008-1805. Reason: This candidate is a reservation duplicate of CVE-2008-1805. Notes: All CVE users should reference CVE-2008-1805 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

около 18 лет назад

Уязвимостей на страницу