Total
5279 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2008-7026 | 1 Efrontlearning | 1 Efront | 2018-10-11 | 6.8 MEDIUM | N/A |
Unrestricted file upload vulnerability in filesystem3.class.php in eFront 3.5.1 build 2710 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension as an avatar, then accessing it via a direct request to the file in (1) student/avatars/ or (2) professor/avatars/. | |||||
CVE-2008-7024 | 1 Arzdev | 2 Gemini Lite, Gemini Portal | 2018-10-11 | 6.8 MEDIUM | N/A |
admin.php in Arz Development The Gemini Portal 4.7 and earlier allows remote attackers to bypass authentication and gain administrator privileges by setting the user cookie to "admin" and setting the name parameter to "users." | |||||
CVE-2008-7212 | 2 Brilaps, Mambo-foundation | 2 Mostlyce, Mambo | 2018-10-11 | 5.0 MEDIUM | N/A |
MOStlyCE before 2.4, as used in Mambo 4.6.3 and earlier, allows remote attackers to obtain sensitive information via certain requests to mambots/editors/mostlyce/jscripts/tiny_mce/filemanager/connectors/php/connector.php, which reveals the installation path in an error message. | |||||
CVE-2008-6736 | 1 Circulargenius | 1 Flat Calendar | 2018-10-11 | 6.4 MEDIUM | N/A |
Flat Calendar 1.1 does not properly restrict access to administrative functions, which allows remote attackers to (1) add new events via calAdd.php, as reachable from admin/add.php, or (2) delete events via admin/deleteEvent.php. NOTE: this is only a vulnerability when the administrator does not follow recommendations in the product's security documentation. | |||||
CVE-2008-6701 | 1 Netscout | 2 Ngenius Infinistream, Visualizer | 2018-10-11 | 7.5 HIGH | N/A |
NetScout (formerly Network General) Visualizer V2100 and InfiniStream i1730 do not restrict access to ResourceManager/en_US/domains/add_domain.jsp, which allows remote attackers to gain administrator privileges via a direct request. | |||||
CVE-2008-6643 | 1 Lokicms | 1 Lokicms | 2018-10-11 | 5.0 MEDIUM | N/A |
LokiCMS 0.3.4 and possibly earlier versions does not properly restrict access to administrative functions, which allows remote attackers to bypass intended restrictions and modify configuration settings via the LokiACTION parameter in a direct request to admin.php. | |||||
CVE-2008-6619 | 1 Netlab | 1 Classsystem | 2018-10-11 | 6.8 MEDIUM | N/A |
Unrestricted file upload vulnerability in class/ApplyDB.php in ClassSystem 2.3 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in class/UploadHomepage/. | |||||
CVE-2008-6617 | 1 Sitexs Cms | 1 Sitexs Cms | 2018-10-11 | 6.8 MEDIUM | N/A |
Unrestricted file upload vulnerability in adm/visual/upload.php in SiteXS CMS 0.1.1 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in images/. | |||||
CVE-2008-6540 | 1 Dotnetnuke | 1 Dotnetnuke | 2018-10-11 | 5.1 MEDIUM | N/A |
DotNetNuke before 4.8.2, during installation or upgrade, does not warn the administrator when the default (1) ValidationKey and (2) DecryptionKey values cannot be modified in the web.config file, which allows remote attackers to bypass intended access restrictions by using the default keys. | |||||
CVE-2008-6051 | 1 Metalinks | 1 Metacart | 2018-10-11 | 5.0 MEDIUM | N/A |
MetaCart Free stores metacart.mdb under the web root with insufficient access control, which allows remote attackers to obtain usernames and passwords via a direct request. | |||||
CVE-2008-6008 | 1 Herongyang | 1 Hybook | 2018-10-11 | 5.0 MEDIUM | N/A |
hyBook Guestbook Script stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing a password via a direct request for hyBook.mdb. | |||||
CVE-2008-5935 | 1 Factosystem | 1 Factosystem Weblog | 2018-10-11 | 5.0 MEDIUM | N/A |
Facto stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing the password via a direct request for database/facto.mdb. NOTE: some of these details are obtained from third party information. | |||||
CVE-2008-5853 | 1 Chicomas | 1 Chicomas | 2018-10-11 | 5.0 MEDIUM | N/A |
Chilek Content Management System (aka ChiCoMaS) 2.0.4 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to (1) obtain database credentials via a direct request for config.inc or (2) read database backups via a request for a backup/ URI. | |||||
CVE-2008-5625 | 1 Php | 1 Php | 2018-10-11 | 7.5 HIGH | N/A |
PHP 5 before 5.2.7 does not enforce the error_log safe_mode restrictions when safe_mode is enabled through a php_admin_flag setting in httpd.conf, which allows context-dependent attackers to write to arbitrary files by placing a "php_value error_log" entry in a .htaccess file. | |||||
CVE-2008-5624 | 1 Php | 1 Php | 2018-10-11 | 7.5 HIGH | N/A |
PHP 5 before 5.2.7 does not properly initialize the page_uid and page_gid global variables for use by the SAPI php_getuid function, which allows context-dependent attackers to bypass safe_mode restrictions via variable settings that are intended to be restricted to root, as demonstrated by a setting of /etc for the error_log variable. | |||||
CVE-2008-5393 | 1 Privacy-cd | 1 Unbuntu Privacy Remix | 2018-10-11 | 10.0 HIGH | N/A |
UPR-Kernel in Ubuntu Privacy Remix (UPR) before 8.04_r1 includes kernel support for mounting RAID arrays, which might allow remote attackers to bypass intended isolation mechanisms by (1) reading from or (2) writing to these arrays. | |||||
CVE-2008-4585 | 1 Belong Software | 1 Site Builder | 2018-10-11 | 7.5 HIGH | N/A |
Belong Software Site Builder 0.1 beta allows remote attackers to bypass intended access restrictions and perform administrative actions via a direct request to admin/home.php. | |||||
CVE-2008-4578 | 1 Dovecot | 1 Dovecot | 2018-10-11 | 5.0 MEDIUM | N/A |
The ACL plugin in Dovecot before 1.1.4 allows attackers to bypass intended access restrictions by using the "k" right to create unauthorized "parent/child/child" mailboxes. | |||||
CVE-2008-4552 | 1 Nfs | 1 Nfs-utils | 2018-10-11 | 7.5 HIGH | N/A |
The good_client function in nfs-utils 1.0.9, and possibly other versions before 1.1.3, invokes the hosts_ctl function with the wrong order of arguments, which causes TCP Wrappers to ignore netgroups and allows remote attackers to bypass intended access restrictions. | |||||
CVE-2008-4512 | 1 Designplace | 1 Asp\/ms Access Shoutbox | 2018-10-11 | 5.0 MEDIUM | N/A |
ASP/MS Access Shoutbox, probably 1.1 beta, stores db/shoutdb.mdb under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request. |