Total
5279 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2008-5602 | 1 Natterchat | 1 Natterchat | 2017-09-28 | 5.0 MEDIUM | N/A |
Natterchat 1.12 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for natterchat112.mdb. | |||||
CVE-2008-5601 | 1 Robs-projects | 1 Asp User Engine | 2017-09-28 | 5.0 MEDIUM | N/A |
User Engine Lite ASP stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for users.mdb. | |||||
CVE-2008-5600 | 1 Merlix | 1 Teamworx Server | 2017-09-28 | 5.0 MEDIUM | N/A |
Merlix Teamworx Server stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for teamworx.mdb. | |||||
CVE-2008-5596 | 1 Dotnetindex | 1 Ikon Admanager | 2017-09-28 | 5.0 MEDIUM | N/A |
Ikon AdManager 2.1 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for ikonBAnner_AdManager.mdb. | |||||
CVE-2008-5592 | 1 Iwrite | 1 Nightfall Personal Diary | 2017-09-28 | 5.0 MEDIUM | N/A |
Nightfall Personal Diary 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for users-zza21.mdb. | |||||
CVE-2008-5572 | 1 Dotnetindex | 1 Professional Download Assistant | 2017-09-28 | 5.0 MEDIUM | N/A |
Professional Download Assistant 0.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for database/downloads.mdb. | |||||
CVE-2008-5562 | 1 Aspapps | 1 Aspportal | 2017-09-28 | 5.0 MEDIUM | N/A |
ASPPortal stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for xportal.mdb. | |||||
CVE-2008-5560 | 1 Dazzlindonna | 1 Postecards | 2017-09-28 | 5.0 MEDIUM | N/A |
PostEcards stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for postcards.mdb. | |||||
CVE-2008-5597 | 1 Cold Bbs | 1 Cold Bbs | 2017-09-28 | 5.0 MEDIUM | N/A |
Cold BBS stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for db/cforum.mdb. | |||||
CVE-2008-5384 | 1 Ibm | 1 Aix | 2017-09-28 | 6.9 MEDIUM | N/A |
crontab in bos.rte.cron in IBM AIX 6.1.0 through 6.1.2 allows local users with aix.system.config.cron authorization to gain privileges by launching an editor. | |||||
CVE-2008-5347 | 1 Sun | 2 Jdk, Jre | 2017-09-28 | 7.5 HIGH | N/A |
Multiple unspecified vulnerabilities in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier allow untrusted applets and applications to gain privileges via vectors related to access to inner classes in the (1) JAX-WS and (2) JAXB packages. | |||||
CVE-2008-5340 | 1 Sun | 3 Jdk, Jre, Sdk | 2017-09-28 | 10.0 HIGH | N/A |
Unspecified vulnerability in Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allows untrusted JWS applications to gain privileges to access local files or applications via unknown vectors, aka 6727081. | |||||
CVE-2008-5351 | 1 Sun | 3 Jdk, Jre, Sdk | 2017-09-28 | 7.5 HIGH | N/A |
Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier accepts UTF-8 encodings that are not the "shortest" form, which makes it easier for attackers to bypass protection mechanisms for other applications that rely on shortest-form UTF-8 encodings. | |||||
CVE-2008-5308 | 1 Lovecms | 2 Lovecms, The Simple Forum | 2017-09-28 | 7.5 HIGH | N/A |
The Simple Forum 3.1d module for LoveCMS 1.6.2 Final does not properly restrict access to administrator functions, which allows remote attackers to change the administrator password via a direct request to modules/simpleforum/admin/index.php. | |||||
CVE-2008-5218 | 1 Scriptsez | 1 Freeze Greetings | 2017-09-28 | 5.0 MEDIUM | N/A |
ScriptsEz FREEze Greetings 1.0 stores pwd.txt under the web root with insufficient access control, which allows remote attackers to obtain cleartext passwords. | |||||
CVE-2008-5127 | 1 Ocean12 Technologies | 1 Contact Manager | 2017-09-28 | 5.0 MEDIUM | N/A |
Ocean12 Contact Manager Pro 1.02 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to o12con.mdb. | |||||
CVE-2008-5121 | 4 Bluecoat, Cisco, Citrix and 1 more | 5 Winproxy, Vpn Client, Deterministic Network Enhancer and 2 more | 2017-09-28 | 7.2 HIGH | N/A |
dne2000.sys in Citrix Deterministic Network Enhancer (DNE) 2.21.7.233 through 3.21.7.17464, as used in (1) Cisco VPN Client, (2) Blue Coat WinProxy, and (3) SafeNet SoftRemote and HighAssurance Remote, allows local users to gain privileges via a crafted DNE_IOCTL DeviceIoControl request to the \\.\DNE device interface. | |||||
CVE-2008-4921 | 1 Chipmunk Scripts | 1 Chipmunk Cms | 2017-09-28 | 7.5 HIGH | N/A |
board/admin/reguser.php in Chipmunk CMS 1.3 allows remote attackers to bypass authentication and gain administrator privileges via a direct request. NOTE: some of these details are obtained from third party information. | |||||
CVE-2008-4644 | 1 Mywebland | 1 Mystats | 2017-09-28 | 7.5 HIGH | N/A |
hits.php in myWebland myStats allows remote attackers to bypass IP address restrictions via a modified X-Forwarded-For HTTP header. | |||||
CVE-2008-4600 | 1 Steve Dawson | 1 Pokermax Poker League Tournament Script | 2017-09-28 | 7.5 HIGH | N/A |
configure.php in PokerMax Poker League Tournament Script 0.13 allows remote attackers to bypass authentication and gain administrative access by setting the ValidUserAdmin cookie. |