CVE-2008-7000 to CVE-2008-7999
152 CVEs with public proof-of-concept exploits.
- CVE-2008-70001 PoCPHP remote file inclusion vulnerability in index.php in PHPAuction 3.2 allows remote attackers to execute arbitrary PHP code via a URL in…
- CVE-2008-70011 PoCUnrestricted file upload vulnerability in the file manager in Creative Mind Creator CMS 5.0 allows remote attackers to execute arbitrary…
- CVE-2008-70021 PoCPHP 5.2.5 does not enforce (a) open_basedir and (b) safe_mode_exec_dir restrictions for certain functions, which might allow local users…
- CVE-2008-70031 PoCMultiple SQL injection vulnerabilities in login.php in The Rat CMS Alpha 2 allow remote attackers to execute arbitrary SQL commands via…
- CVE-2008-70052 PoCsinclude/modules/top/1-random_quote.php in Minb Is Not a Blog (minb) 0.1.0 allows remote attackers to execute arbitrary PHP code via the…
- CVE-2008-70061 PoCFree PHP VX Guestbook 1.06 allows remote attackers to bypass authentication and download a backup of the database via a direct request to…
- CVE-2008-70071 PoCFree PHP VX Guestbook 1.06 allows remote attackers to bypass authentication and gain administrative access by setting the (1) admin_name…
- CVE-2008-70081 PoCHyperStop Web Host Directory 1.2 allows remote attackers to bypass authentication and download a database backup via a direct request to…
- CVE-2008-70091 PoCBuffer overflow in multiscan.exe in Check Point ZoneAlarm Security Suite 7.0.483.000 and 8.0.020.000 allows local users to execute…
- CVE-2008-70101 PoCSkalfa Software SkaLinks Exchange Script 1.5 allows remote attackers to add new administrators and gain privileges via a direct request to…
- CVE-2008-70111 PoCThe Unreal engine, as used in Unreal Tournament 3 1.3, Unreal Tournament 2003 and 2004, Dead Man's Hand, Pariah, WarPath, Postal2, and…
- CVE-2008-70121 PoCcourier/1000@/api_error_email.html (aka "error reporting page") in Accellion File Transfer Appliance FTA_7_0_178, and possibly other…
- CVE-2008-70141 PoCfhttpd 0.4.2 allows remote attackers to cause a denial of service (crash) via an Authorization HTTP header with an invalid character after…
- CVE-2008-70151 PoCUnreal engine 3, as used in Unreal Tournament 3 1.3, Frontlines: Fuel of War 1.1.1, and other products, allows remote attackers to cause a…
- CVE-2008-70171 PoCCross-site scripting (XSS) vulnerability in analyse.php in CAcert 20080921, and possibly other versions before 20080928, allows remote…
- CVE-2008-70191 PoCEsqlanelapse 2.6.1 and 2.6.2 allows remote attackers to bypass authentication and gain privileges via modified (1) enombre and (2) euri…
- CVE-2008-70211 PoCUnrestricted file upload vulnerability in editlogo.php in AvailScript Jobs Portal Script allows remote authenticated users to execute…
- CVE-2008-70221 PoCInsecure method vulnerability in ChilkatMail_v7_9.dll in the Chilkat Software IMAP ActiveX control (ChilkatMail2.ChilkatMailMan2.1) allows…
- CVE-2008-70241 PoCadmin.php in Arz Development The Gemini Portal 4.7 and earlier allows remote attackers to bypass authentication and gain administrator…
- CVE-2008-70251 PoCTrueVector in Check Point ZoneAlarm 8.0.020.000, with vsmon.exe running, allows remote HTTP proxies to cause a denial of service (crash)…
- CVE-2008-70261 PoCUnrestricted file upload vulnerability in filesystem3.class.php in eFront 3.5.1 build 2710 and earlier allows remote attackers to execute…
- CVE-2008-70271 PoCLibra File Manager 1.18 and earlier allows remote attackers to bypass authentication and gain privileges by setting the user and pass…
- CVE-2008-70281 PoCRPG.Board 0.8 Beta2 and earlier allows remote attackers to bypass authentication and gain privileges by setting the keep4u cookie to a…
- CVE-2008-70302 PoCsMultiple SQL injection vulnerabilities in Site2Nite Real Estate Web allow remote attackers to execute arbitrary SQL commands via the (1)…
- CVE-2008-70311 PoCHeap-based buffer overflow in Foxit Remote Access Server (aka WAC Server) 2.0 Build 3503 allows remote attackers to cause a denial of…
- CVE-2008-70321 PoCWeb Management Console Cross-site request forgery (CSRF) vulnerability in the web management console in F5 BIG-IP 9.4.3 allows remote…
- CVE-2008-70331 PoCSQL injection vulnerability in the Simple Shop Galore (com_simpleshop) component for Joomla! allows remote attackers to execute arbitrary…
- CVE-2008-70361 PoCMultiple cross-site scripting (XSS) vulnerabilities in index.php in DevTracker module 3.0 for bcoos 1.1.11 and earlier, and DevTracker…
- CVE-2008-70382 PoCsSQL injection vulnerability in the My_eGallery module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the gid…
- CVE-2008-70401 PoCSQL injection vulnerability in ahah/sf-profile.php in the Yellow Swordfish Simple Forum module for Wordpress allows remote attackers to…
- CVE-2008-70411 PoCAJ Classifieds allows remote attackers to bypass authentication and gain administrator privileges via a direct request to admin/home.php.
- CVE-2008-70421 PoCPHP remote file inclusion vulnerability in url.php in FreshScripts Fresh Email Script 1.0 through 1.11 allows remote attackers to execute…
- CVE-2008-70431 PoCCross-site scripting (XSS) vulnerability in register.php in FreshScripts Fresh Email Script 1.0 through 1.11 allows remote attackers to…
- CVE-2008-70441 PoCSQL injection vulnerability in admin/include/newpoll.php in AJ Square Free Polling Script (AJPoll) Database version allows remote…
- CVE-2008-70451 PoCAJ Square Free Polling Script (AJPoll) Database version allows remote attackers to bypass authentication and reset poll votes via a direct…
- CVE-2008-70461 PoCAJ Square Free Polling Script (AJPoll) allows remote attackers to bypass authentication and create new polls via a direct request to…
- CVE-2008-70471 PoCNatterChat 1.1 allows remote attackers to bypass authentication and gain administrator privileges to read or delete rooms and messages via…
- CVE-2008-70492 PoCsMultiple SQL injection vulnerabilities in login.asp in NatterChat 1.1 and 1.12 allow remote attackers to execute arbitrary SQL commands…
- CVE-2008-70511 PoCAJ Square AJ Article allows remote attackers to bypass authentication and access administrator functionality via a direct request to (1)…
- CVE-2008-70521 PoCUnrestricted file upload vulnerability in profile.php in Pre Projects Pre Real Estate Listings allows remote authenticated users to…
- CVE-2008-70531 PoCLogMeIn Remote Access Utility ActiveX control (RACtrl.dll) allows remote attackers to cause a denial of service (crash) by setting the…
- CVE-2008-70541 PoCMultiple directory traversal vulnerabilities in ezContents 2.0.3 allow remote attackers to include and execute arbitrary local files via…
- CVE-2008-70551 PoCmodule.php in ezContents 2.0.3 allows remote attackers to bypass the directory traversal protection mechanism to include and execute…
- CVE-2008-70561 PoCBandSite CMS 1.1.4 does not perform access control for adminpanel/phpmydump.php, which allows remote attackers to obtain copies of the…
- CVE-2008-70571 PoCCross-site scripting (XSS) vulnerability in merchandise.php in BandSite CMS 1.1.4 allows remote attackers to inject arbitrary HTML or web…
- CVE-2008-70581 PoCCross-site request forgery (CSRF) vulnerability in BandSite CMS 1.1.4 allows remote attackers to hijack the authentication of…
- CVE-2008-70592 PoCsSQL injection vulnerability in index.php in One-News Beta 2 allows remote attackers to execute arbitrary SQL commands via the q parameter.
- CVE-2008-706111 PoCsThe tooltip manager (chrome/views/tooltip_manager.cc) in Google Chrome 0.2.149.29 Build 1798 and possibly other versions before 0.2.149.30…
- CVE-2008-70621 PoCUnrestricted file upload vulnerability in admin/index.php in Download Manager module 1.0 for LoveCMS 1.6.2 Final allows remote attackers…
- CVE-2008-70631 PoCOcean12 FAQ Manager Pro stores sensitive data under the web root with insufficient access control, which allows remote attackers to…
- CVE-2008-70641 PoCDirectory traversal vulnerability in the get_lang function in global.php in Quicksilver Forums 1.4.2 and earlier, as used in QSF Portal…
- CVE-2008-70651 PoCSiemens C450 IP and C475 IP VoIP devices allow remote attackers to cause a denial of service (disconnected calls and device reboot) via a…
- CVE-2008-70661 PoCOpenForum 0.66 Beta allows remote attackers to bypass authentication and reset passwords of other users via a direct request with the…
- CVE-2008-70671 PoCPHP remote file inclusion vulnerability in admin/plugins/Online_Users/main.php in PageTree CMS 0.0.2 BETA 0001 allows remote attackers to…
- CVE-2008-70691 PoCAll Club CMS (ACCMS) 0.0.2 and earlier stores sensitive information under the web root with insufficient access control, which allows…
- CVE-2008-70702 PoCsArgument injection vulnerability in the URI handler in KVIrc 3.4.2 Shiny allows remote attackers to execute arbitrary commands via a "…
- CVE-2008-70711 PoCSQL injection vulnerability in authenticate.php in Chipmunk Topsites allows remote attackers to execute arbitrary SQL commands via the…
- CVE-2008-70721 PoCCross-site scripting (XSS) vulnerability in index.php in Chipmunk Topsites allows remote attackers to inject arbitrary web script or HTML…
- CVE-2008-70731 PoCPHP remote file inclusion vulnerability in lib/action/rss.php in RSS module 0.1 for Pie Web M{a,e}sher, when register_globals is enabled,…
- CVE-2008-70741 PoCFormat string vulnerability in MemeCode Software i.Scribe 1.88 through 2.00 before Beta9 allows remote SMTP servers to cause a denial of…
- CVE-2008-70752 PoCsMultiple SQL injection vulnerabilities in Kalptaru Infotech Ltd. Star Articles 6.0 allow remote attackers to inject arbitrary SQL commands…
- CVE-2008-70761 PoCUnrestricted file upload vulnerability in user.modify.profile.php in Kalptaru Infotech Ltd. Star Articles 6.0 allows remote authenticated…
- CVE-2008-70771 PoCMultiple SQL injection vulnerabilities in SailPlanner 0.3a allow remote attackers to execute arbitrary SQL commands via the (1) username…
- CVE-2008-70781 PoCMultiple buffer overflows in Rumpus before 6.0.1 allow remote attackers to (1) cause a denial of service (segmentation fault) via a long…
- CVE-2008-70791 PoCBuffer overflow in Nero ShowTime 5.0.15.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code…
- CVE-2008-70801 PoCTeam PHP PHP Classifieds Script stores sensitive information under the web root with insufficient access control, which allows remote…
- CVE-2008-70831 PoCMultiple SQL injection vulnerabilities in ReVou Micro Blogging Twitter clone allow remote attackers to execute arbitrary SQL commands via…
- CVE-2008-70841 PoCDirectory traversal vulnerability in the web server 1.0 in Velocity Security Management System allows remote attackers to read arbitrary…
- CVE-2008-70851 PoCMultiple SQL injection vulnerabilities in TheHockeyStop HockeySTATS Online 2.0 Basic and Advanced allow remote attackers to execute…
- CVE-2008-70861 PoCMaian Greetings 2.1 allows remote attackers to bypass authentication and gain administrative privileges by setting the mecard_admin_cookie…
- CVE-2008-70871 PoCPHP remote file inclusion vulnerability in search_wA.php in OpenPro 1.3.1 allows remote attackers to execute arbitrary PHP code via a URL…
- CVE-2008-70881 PoCUnrestricted file upload vulnerability in upload.php in PhotoPost vBGallery 2.4.2 allows remote authenticated users to execute arbitrary…
- CVE-2008-70891 PoCCross-site scripting (XSS) vulnerability in Pligg 9.9 and earlier allows remote attackers to inject arbitrary web script or HTML via the…
- CVE-2008-70901 PoCMultiple directory traversal vulnerabilities in Pligg 9.9 and earlier allow remote attackers to (1) determine the existence of arbitrary…
- CVE-2008-70912 PoCsMultiple SQL injection vulnerabilities in Pligg 9.9 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id…
- CVE-2008-70971 PoCMultiple SQL injection vulnerabilities in Qsoft K-Rate Premium allow remote attackers to execute arbitrary SQL commands via (1) the $id…
- CVE-2008-70981 PoCMultiple cross-site scripting (XSS) vulnerabilities in Qsoft K-Rate Premium allow remote attackers to inject arbitrary web script or HTML…
- CVE-2008-70991 PoCUnspecified vulnerability in the Manage Templates feature in Qsoft K-Rate Premium allows remote attackers to execute arbitrary PHP code…
- CVE-2008-71031 PoCStack-based buffer overflow in an ActiveX control in najdisitoolbar.dll in Najdi.si Toolbar 2.0.4.1 allows remote attackers to cause a…
- CVE-2008-71071 PoCeasdrv.sys in ESET Smart Security 3.0.667.0 allows local users to cause a denial of service (crash) via a crafted IOCTL 0x222003 request…
- CVE-2008-71101 PoCDirectory traversal vulnerability in the Scanner File Utility (aka listener) in Kyocera Mita (KM) 3.3.0.1 allows remote attackers to…
- CVE-2008-71141 PoCSQL injection vulnerability in members_search.php in iFusion Services iFdate 2.0.3 and earlier allows remote attackers to execute…
- CVE-2008-71151 PoCThe web interface to the Belkin Wireless G router and ADSL2 modem F5D7632-4V6 with firmware 6.01.08 allows remote attackers to bypass…
- CVE-2008-71161 PoCSQL injection vulnerability in the admin panel (admin/) in WeBid auction script 0.5.4 allows remote attackers to execute arbitrary SQL…
- CVE-2008-71171 PoCeledicss.php in WeBid auction script 0.5.4 allows remote attackers to modify arbitrary cascading style sheets (CSS) files via a certain…
- CVE-2008-71181 PoCWeBid auction script 0.5.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers…
- CVE-2008-71191 PoCSQL injection vulnerability in item.php in WeBid auction script 0.5.4 allows remote attackers to execute arbitrary SQL commands via the id…
- CVE-2008-71201 PoCSQL injection vulnerability in Mr. CGI Guy Hot Links SQL-PHP 3 and earlier allows remote attackers to execute arbitrary SQL commands via…
- CVE-2008-71221 PoCMultiple insecure method vulnerabilities in an ActiveX control in (epRegPro.ocx) in Evans Programming Registry Pro allow remote attackers…
- CVE-2008-71231 PoCStatic code injection vulnerability in admin/configuration/modifier.php in zKup CMS 2.0 through 2.3 allows remote attackers to inject…
- CVE-2008-71242 PoCszKup CMS 2.0 through 2.3 does not require administrative authentication for admin/configuration/modifier.php, which allows remote…
- CVE-2008-71261 PoCInteger overflow in osagent.exe in Borland VisiBroker Smart Agent 08.00.00.C1.03 and earlier allows remote attackers to cause a denial of…
- CVE-2008-71334 PoCsMultiple cross-site scripting (XSS) vulnerabilities in onlinetools.org EasyImageCatalogue 1.3.1 allow remote attackers to inject arbitrary…
- CVE-2008-71343 PoCsMultiple cross-site scripting (XSS) vulnerabilities in the default URI in Chris LaPointe RedGalaxy Download Center 1.2 allow remote…
- CVE-2008-71351 PoCtoolbaru.dll in ICQ Toolbar (ICQToolbar) 2.3 allows remote attackers to cause a denial of service (toolbar crash) via a long argument to…
- CVE-2008-71361 PoCtoolbaru.dll in ICQ Toolbar (ICQToolbar) 2.3 allows remote attackers to cause a denial of service (toolbar crash) via a long argument to…
- CVE-2008-71402 PoCsMultiple cross-site scripting (XSS) vulnerabilities in @lex Guestbook 4.0.5 and earlier allow remote attackers to inject arbitrary web…
- CVE-2008-71411 PoCCross-site scripting (XSS) vulnerability in setup.php in @lex Poll 2.1 allows remote attackers to inject arbitrary web script or HTML via…
- CVE-2008-71421 PoCAbsolute path traversal vulnerability in the Disk Usage module (frontend/x/diskusage/index.html) in cPanel 11.18.3 allows remote attackers…
- CVE-2008-71451 PoCMultiple SQL injection vulnerabilities in index.php in CoronaMatrix phpAddressBook 2.0 allow remote attackers to execute arbitrary SQL…
- CVE-2008-71522 PoCsMultiple PHP remote file inclusion vulnerabilities in Specimen Image Database (SID), when register_globals is enabled, allow remote…
- CVE-2008-71532 PoCsSQL injection vulnerability in the autoDetectRegion function in doceboCore/lib/lib.regset.php in Docebo 3.5.0.3 and earlier allows remote…
- CVE-2008-71541 PoCDocebo 3.5.0.3 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) class/class.conf_fw.php,…
- CVE-2008-71551 PoCNetRisk 1.9.7 does not properly restrict access to admin/change_submit.php, which allows remote attackers to change the password of…
- CVE-2008-71561 PoCEkinBoard 1.1.0 and earlier, when register_globals is enabled, allows remote attackers to bypass authorization and gain administrator…
- CVE-2008-71571 PoCUnrestricted file upload vulnerability in EkinBoard 1.1.0 and earlier allows remote attackers to execute arbitrary code by uploading an…
- CVE-2008-71611 PoCFortinet FortiGuard Fortinet FortiGate-1000 3.00 build 040075,070111 allows remote attackers to bypass URL filtering via fragmented GET or…
- CVE-2008-71621 PoCBuffer overflow in Hero Super Player 3000 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code…
- CVE-2008-71631 PoCDirectory traversal vulnerability in mods/Integrated/index.php in SineCMS 2.3.5 and earlier, when register_globals is enabled, allows…
- CVE-2008-71651 PoCCross-site request forgery in cp06_wifi_m_nocifr.cgi in the administrator panel in TELECOM ITALIA Alice Gate2 Plus Wi-Fi allows remote…
- CVE-2008-71671 PoCUnrestricted file upload vulnerability in upload.php in Page Manager 2006-02-04 allows remote attackers to execute arbitrary code by…
- CVE-2008-71681 PoCInsecure method vulnerability in the UUSee UUUpgrade ActiveX control (UUUpgrade.ocx 3.0.2.12) allows remote attackers to force the…
- CVE-2008-71691 PoCSQL injection vulnerability in Jabode horoscope extension (com_jabode) for Joomla! allows remote attackers to execute arbitrary SQL…
- CVE-2008-71702 PoCsGSC build 2067 and earlier relies on the client to enforce administrator privileges, which allows remote attackers to execute arbitrary…
- CVE-2008-71711 PoCMultiple cross-site scripting (XSS) vulnerabilities in Lightweight news portal (LNP) 1.0b allow remote attackers to inject arbitrary web…
- CVE-2008-71721 PoCLightweight news portal (LNP) 1.0b does not properly restrict access to administrator functionality, which allows remote attackers to gain…
- CVE-2008-71762 PoCsMultiple directory traversal vulnerabilities in Facil CMS 0.1RC allow remote attackers to read arbitrary files via a .. (dot dot) in the…
- CVE-2008-71781 PoCDirectory traversal vulnerability in Uploader module 1.1 for XOOPS allows remote attackers to read arbitrary files via a .. (dot dot) in…
- CVE-2008-71791 PoCOTManager CMS 2.4 allows remote attackers to bypass authentication and gain administrator privileges by setting the ADMIN_Hora,…
- CVE-2008-71801 PoCdel_query1.php in Telephone Directory 2008 allows remote attackers to delete arbitrary contacts via a direct request with a modified id…
- CVE-2008-71811 PoCButterfly Organizer 2.0.0 allows remote attackers to (1) delete arbitrary categories via a modified tablehere parameter to…
- CVE-2008-71821 PoCBuffer overflow in the IMAP service in NetWin Surgemail 3.9e, and possibly other versions before 3.9g2, allows remote authenticated users…
- CVE-2008-71841 PoCCross-site scripting (XSS) vulnerability in Diigo Toolbar and Diigolet allows remote attackers to inject arbitrary web script or HTML via…
- CVE-2008-71851 PoCGNOME Rhythmbox 0.11.5 allows remote attackers to cause a denial of service (segmentation fault and crash) via a playlist (.pls) file with…
- CVE-2008-71881 PoCClipShare 2.6 does not properly restrict access to certain functionality, which allows remote attackers to change the profile of arbitrary…
- CVE-2008-71921 PoCCross-site request forgery (CSRF) vulnerability in index.php in WoltLab Burning Board (wBB) 3.0.1, and possibly other 3.x versions, allows…
- CVE-2008-72031 PoCValve Software Half-Life Counter-Strike 1.6 allows remote attackers to cause a denial of service (crash) via multiple crafted login packets.
- CVE-2008-72081 PoCMultiple SQL injection vulnerabilities in OneCMS 2.4, and possibly earlier, allow remote attackers to execute arbitrary SQL commands via…
- CVE-2008-72091 PoCUnrestricted file upload vulnerability in the add2 action in a_upload.php in OneCMS 2.4, and possibly earlier, allows remote attackers to…
- CVE-2008-72101 PoCdirectory.php in AJchat 0.10 allows remote attackers to bypass input validation and conduct SQL injection attacks via a numeric parameter…
- CVE-2008-72111 PoCCreativeLabs es1371mp.sys 5.1.3612.0 WDM audio driver, as used in Ensoniq PCI 1371 sound cards and when running on Windows Vista, does not…
- CVE-2008-72131 PoCCross-site scripting (XSS) vulnerability in mambots/editors/mostlyce/jscripts/tiny_mce/filemanager/connectors/php/connector.php in…
- CVE-2008-72161 PoCPeter's Math Anti-Spam Spinoff plugin for WordPress generates audio CAPTCHA clips by concatenating static audio files without any…
- CVE-2008-72201 PoCUnspecified vulnerability in Prototype JavaScript framework (prototypejs) before 1.6.0.2 allows attackers to make "cross-site ajax…
- CVE-2008-72221 PoCCross-site scripting (XSS) vulnerability in system/admin.php in RunCMS 1.6.1 allows remote attackers to inject arbitrary web script or…
- CVE-2008-72261 PoCSQL injection vulnerability in index.php in the Recipes module 1.3, 1.4, and possibly other versions for PHP-Nuke allows remote attackers…
- CVE-2008-72323 PoCsBuffer overflow in the report function in xtacacsd 4.1.2 and earlier allows remote attackers to execute arbitrary code via a crafted…
- CVE-2008-72401 PoCDirectory traversal vulnerability in include/unverified.inc.php in Linux Web Shop (LWS) php User Base 1.3beta allows remote attackers to…
- CVE-2008-72421 PoCMultiple cross-site scripting (XSS) vulnerabilities in MODx CMS 0.9.6.1 and 0.9.6.1p1 allo remote attackers to inject arbitrary web script…
- CVE-2008-72441 PoCMozilla Firefox 3.0.1 and earlier allows remote attackers to cause a denial of service (browser hang) by calling the window.print function…
- CVE-2008-72451 PoCOpera 9.52 and earlier allows remote attackers to cause a denial of service (unusable browser) by calling the window.print function in a…
- CVE-2008-72461 PoCGoogle Chrome 0.2.149.29 and earlier allows remote attackers to cause a denial of service (unusable browser) by calling the window.print…
- CVE-2008-72481 PoCRuby on Rails 2.1 before 2.1.3 and 2.2.x before 2.2.2 does not verify tokens for requests with certain content types, which allows remote…
- CVE-2008-72542 PoCsDirectory traversal vulnerability in includes/template-loader.php in Irmin CMS (formerly Pepsi CMS) 0.5 and 0.6 BETA2, when…
- CVE-2008-72571 PoCCRLF injection vulnerability in +webvpn+/index.html in WebVPN on Cisco Adaptive Security Appliances (ASA) 5580 series devices with…
- CVE-2008-72581 PoCThe standardise function in Anibal Monsalve Salazar sSMTP 2.61 and 2.62 allows local users to cause a denial of service (application exit)…
- CVE-2008-72641 PoCThe ftp_QUIT function in ftpserver.py in pyftpdlib before 0.5.0 allows remote authenticated users to cause a denial of service (file…
- CVE-2008-72672 PoCsSQL injection vulnerability in announcements.php in SiteEngine 5.x allows remote attackers to execute arbitrary SQL commands via the id…
- CVE-2008-72681 PoCThe phpinfo function in SiteEngine 5.x allows remote attackers to obtain system information by setting the action parameter to php_info in…
- CVE-2008-72693 PoCsOpen redirect vulnerability in api.php in SiteEngine 5.x allows user-assisted remote attackers to redirect users to arbitrary web sites…
- CVE-2008-72713 PoCsMultiple cross-site scripting (XSS) vulnerabilities in the Help Contents web application (aka the Help Server) in Eclipse IDE, possibly…
- CVE-2008-73011 PoCSQL injection vulnerability in admin/login.php in jSite 1.0 OE allows remote attackers to execute arbitrary SQL commands via the username…