Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2008-6129 | 1 Mozilo | 1 Mozilowiki | 2017-08-16 | 4.3 MEDIUM | N/A |
Directory traversal vulnerability in print.php in moziloWiki 1.0.1 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter. | |||||
CVE-2008-6130 | 1 Mozilo | 1 Mozilowiki | 2017-08-16 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in index.php in moziloWiki 1.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) action and (2) page parameters. | |||||
CVE-2008-6131 | 1 Mozilo | 1 Mozilowiki | 2017-08-16 | 6.0 MEDIUM | N/A |
Session fixation vulnerability in moziloWiki 1.0.1 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter. | |||||
CVE-2008-6134 | 1 Drupal | 2 Drupal, Everyblog | 2017-08-16 | 7.5 HIGH | N/A |
SQL injection vulnerability in EveryBlog 5.x and 6.x, a module for Drupal, allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |||||
CVE-2008-6135 | 1 Drupal | 2 Drupal, Everyblog | 2017-08-16 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in EveryBlog 5.x and 6.x, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |||||
CVE-2008-6136 | 1 Drupal | 1 Everyblog | 2017-08-16 | 7.5 HIGH | N/A |
Unspecified vulnerability in EveryBlog 5.x and 6.x, a module for Drupal, allows remote attackers to gain privileges as another user or an administrator via unknown attack vectors. | |||||
CVE-2008-6137 | 1 Drupal | 2 Drupal, Everyblog | 2017-08-16 | 7.5 HIGH | N/A |
EveryBlog 5.x and 6.x, a module for Drupal, allows remote attackers to bypass access restrictions via unknown vectors. | |||||
CVE-2008-6140 | 1 Avaya | 1 One-x | 2017-08-16 | 5.0 MEDIUM | N/A |
Unspecified vulnerability in the Session Initiation Protocol (SIP) implementation in Avaya one-X Desktop Edition 2.1.0.78 allows remote attackers to cause a denial of service (crash) via unspecified vectors. | |||||
CVE-2008-6141 | 1 Avaya | 1 Ip Soft Phone | 2017-08-16 | 5.0 MEDIUM | N/A |
Unspecified vulnerability in Avaya IP Softphone 6.0 SP4 and 6.01.85 allows remote attackers to cause a denial of service (crash) via a large amount of H.323 data. | |||||
CVE-2008-6155 | 1 Hispah | 1 Text Links Ads | 2017-08-16 | 7.5 HIGH | N/A |
SQL injection vulnerability in index.php in Hispah Text Links Ads 1.1 allows remote attackers to execute arbitrary SQL commands via the idtl parameter in a buy action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |||||
CVE-2008-6158 | 1 W3bcms | 1 W3b\>cms | 2017-08-16 | 10.0 HIGH | N/A |
Multiple unspecified vulnerabilities in the admin backend in w3b>cms (aka w3blabor CMS) before 3.2.0 have unknown impact and remote attack vectors. | |||||
CVE-2008-6160 | 1 Drupal | 1 Semantically Interconnected Online Communities | 2017-08-16 | 5.0 MEDIUM | N/A |
Semantically-Interconnected Online Communities (SIOC) 5.x before 5.x-1.2 and 6.x before 6.x-1.1, a module for Drupal, does not properly implement menu and database APIs, which allows remote attackers to obtain usernames and read hashed emails and comments via unspecified vectors. | |||||
CVE-2008-6169 | 1 Drupal | 2 Localization Client, Localization Server | 2017-08-16 | 6.8 MEDIUM | N/A |
Cross-site request forgery (CSRF) vulnerability in the Localization client 5.x before 5.x-1.1 and 6.x before 6.x-1.6 and the Localization server 5.x before 5.x-1.0-alpha5 and 6.x before 6.x-alpha2, modules for Drupal, allows remote attackers to perform unauthorized actions as administrators via unspecified vectors related to the "local translation submission interface." | |||||
CVE-2008-6170 | 1 Drupal | 1 Drupal | 2017-08-16 | 3.5 LOW | N/A |
Cross-site scripting (XSS) vulnerability in Drupal 5.x before 5.12 and 6.x before 6.6 allows remote authenticated users with create book content or edit node book hierarchy permissions to inject arbitrary web script or HTML via the book page title. | |||||
CVE-2008-6171 | 1 Drupal | 1 Drupal | 2017-08-16 | 9.3 HIGH | N/A |
includes/bootstrap.inc in Drupal 5.x before 5.12 and 6.x before 6.6, when the server is configured for "IP-based virtual hosts," allows remote attackers to include and execute arbitrary files via the HTTP Host header. | |||||
CVE-2008-6173 | 1 Clip-share | 1 Clipshare | 2017-08-16 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in fullscreen.php in ClipShare Pro 4.0 allows remote attackers to inject arbitrary web script or HTML via the title parameter. | |||||
CVE-2008-6174 | 1 Jetbox | 1 Jetbox Cms | 2017-08-16 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in admin/postlister/index.php in Jetbox CMS 2.1 allows remote attackers to inject arbitrary web script or HTML via the liste parameter. | |||||
CVE-2008-6189 | 1 Gforge | 1 Gforge | 2017-08-16 | 7.5 HIGH | N/A |
SQL injection vulnerability in GForge 4.5.19 allows remote attackers to execute arbitrary SQL commands via the offset parameter to (1) new/index.php, (2) news/index.php, and (3) top/topusers.php, which is not properly handled in database-pgsql.php. | |||||
CVE-2008-6190 | 1 Eeb-welt | 1 Eebcms | 2017-08-16 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in index.php in EEBCMS 0.95 allows remote attackers to inject arbitrary web script or HTML via the content parameter. | |||||
CVE-2008-6191 | 1 Intrinsic | 1 Swimage Encore | 2017-08-16 | 2.1 LOW | N/A |
Conductor.exe in Intrinsic Swimage Encore before 5.0.1.21 contains a hardcoded password, which might allow local users to decrypt certain .bin files. NOTE: it is not clear whether this issue crosses privilege boundaries. |