Total
5279 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2008-3508 | 1 Wogan May | 1 Litenews | 2017-09-28 | 5.0 MEDIUM | N/A |
LiteNews 0.1 (aka 01), and possibly 1.2 and earlier, allows remote attackers to bypass authentication and gain administrative access by setting the admin cookie. | |||||
CVE-2008-3454 | 1 Jnshosts | 1 Php Hosting Directory | 2017-09-28 | 7.5 HIGH | N/A |
JnSHosts PHP Hosting Directory 2.0 allows remote attackers to bypass authentication and gain administrative access by setting the "adm" cookie value to 1. | |||||
CVE-2008-3303 | 1 Tuxplanet | 1 Bilboblog | 2017-09-28 | 6.8 MEDIUM | N/A |
admin/login.php in BilboBlog 0.2.1, when register_globals is enabled, allows remote attackers to bypass authentication and obtain administrative access via a direct request that sets the login, admin_login, password, and admin_passwd parameters. | |||||
CVE-2008-3279 | 1 Mielke | 1 Brltty | 2017-09-28 | 6.9 MEDIUM | N/A |
Untrusted search path vulnerability in libbrlttybba.so in brltty 3.7.2 allows local users to gain privileges via a crafted library, related to an incorrect RPATH setting. | |||||
CVE-2008-3234 | 2 Debian, Openbsd | 2 Debian Linux, Openssh | 2017-09-28 | 6.5 MEDIUM | N/A |
sshd in OpenSSH 4 on Debian GNU/Linux, and the 20070303 OpenSSH snapshot, allows remote authenticated users to obtain access to arbitrary SELinux roles by appending a :/ (colon slash) sequence, followed by the role name, to the username. | |||||
CVE-2008-3156 | 1 Panda | 1 Panda Activescan | 2017-09-28 | 9.3 HIGH | N/A |
The ActiveScan ActiveX Control (as2guiie.dll) in Panda ActiveScan before 1.02.00 allows remote attackers to download and execute arbitrary cabinet (CAB) files via unspecified URLs passed to the Update method. | |||||
CVE-2008-2940 | 1 Hp | 1 Linux Imaging And Printing Project | 2017-09-28 | 7.2 HIGH | N/A |
The alert-mailing implementation in HP Linux Imaging and Printing (HPLIP) 1.6.7 allows local users to gain privileges and send e-mail messages from the root account via vectors related to the setalerts message, and lack of validation of the device URI associated with an event message. | |||||
CVE-2008-2682 | 1 Realm Project | 1 Realm Cms | 2017-09-28 | 7.5 HIGH | N/A |
_RealmAdmin/login.asp in Realm CMS 2.3 and earlier allows remote attackers to bypass authentication and access admin pages via certain modified cookies, probably including (1) cUserRole, (2) cUserName, and (3) cUserID. | |||||
CVE-2008-2515 | 1 Ibm | 1 Aix | 2017-09-28 | 7.2 HIGH | N/A |
Unspecified vulnerability in iostat in IBM AIX 5.2, 5.3, and 6.1 allows local users to gain privileges via unknown vectors related to an "environment variable handling error." | |||||
CVE-2008-2488 | 1 Beaussier | 1 Roomphplanning | 2017-09-28 | 6.5 MEDIUM | N/A |
admin/userform.php in RoomPHPlanning 1.5 does not require administrative credentials, which allows remote authenticated users to create new admin accounts. | |||||
CVE-2008-2349 | 1 Zomp | 1 Zomplog | 2017-09-28 | 7.5 HIGH | N/A |
Zomplog 3.8.2 and earlier allows remote attackers to gain administrative access by creating an admin account via a direct request to install/newuser.php with the admin parameter set to 1. | |||||
CVE-2008-2348 | 1 Meltingicefs | 1 Meltingice File System | 2017-09-28 | 7.5 HIGH | N/A |
MeltingIce File System 1.0 allows remote attackers to bypass application authentication, create new user accounts, and exceed application quotas via a direct request to admin/adduser.php. | |||||
CVE-2008-2346 | 1 Alkalinephp | 1 Alkalinephp | 2017-09-28 | 7.5 HIGH | N/A |
AlkalinePHP 0.77.35 and earlier allows remote attackers to bypass authentication and gain administrative access by creating an admin account via a direct request to adduser.php. | |||||
CVE-2008-2343 | 1 News Manager | 1 News Manager | 2017-09-28 | 7.5 HIGH | N/A |
News Manager 2.0 allows remote attackers to bypass restrictions and obtain sensitive information via a direct request to (1) db/connect_str.php and (2) login/info.php. | |||||
CVE-2008-2338 | 1 Interspire | 1 Activekb | 2017-09-28 | 7.5 HIGH | N/A |
Interspire ActiveKB 1.5 and earlier allows remote attackers to gain privileges by setting the auth cookie to true when accessing unspecified scripts in /admin. | |||||
CVE-2008-2294 | 1 Mreaves | 1 Pet Grooming Management System | 2017-09-28 | 7.5 HIGH | N/A |
Pet Grooming Management System 2.0 allows remote attackers to gain privileges via a direct request to useradded.php with a modified user name for "admin." | |||||
CVE-2008-2297 | 1 Roticv | 1 Rantx | 2017-09-28 | 7.5 HIGH | N/A |
The admin.php file in Rantx allows remote attackers to bypass authentication and gain privileges by setting the logininfo cookie to "<?php" or "?>", which is present in the password file and probably passes an insufficient comparison. | |||||
CVE-2008-2293 | 1 Tpvgames | 1 Mpcs | 2017-09-28 | 7.5 HIGH | N/A |
admin.php in Multi-Page Comment System (MPCS) 1.0 and 1.1 allows remote attackers to bypass authentication and gain privileges by setting the CommentSystemAdmin cookie to 1. | |||||
CVE-2008-2216 | 1 Pbcs | 1 Project-based Calendaring System | 2017-09-28 | 9.0 HIGH | N/A |
Unrestricted file upload vulnerability in src/yopy_upload.php in Project-Based Calendaring System (PBCS) 0.7.1 allows remote authenticated users to upload arbitrary files to tmp/uploads. | |||||
CVE-2008-0805 | 1 Reality | 1 Medias Phpizabi | 2017-09-28 | 9.3 HIGH | N/A |
Unrestricted file upload vulnerability in image.php in PHPizabi 0.848b C1 HFP1 allows remote attackers to execute arbitrary code by uploading a file with an executable extension from the event page, then accessing it via a direct request to the file in system/cache/pictures. |