Total
5458 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2008-0569 | 1 Drupal | 1 Comment Upload Module | 2024-11-21 | N/A |
The Comment Upload 4.7.x before 4.7.x-0.1 and 5.x before 5.x-0.1 module for Drupal does not properly use functions in the upload module, which allows remote attackers to bypass upload validation, and upload arbitrary files and possibly execute arbitrary code, via unspecified vectors. | ||||
CVE-2008-0556 | 1 Openca | 1 Openca Pki | 2024-11-21 | N/A |
Cross-site request forgery (CSRF) vulnerability in OpenCA PKI 0.9.2.5, and possibly earlier versions, allows remote attackers to perform unauthorized actions as authorized users via a link or IMG tag to RAServer. | ||||
CVE-2008-0425 | 1 Frimousse | 1 Frimousse | 2024-11-21 | N/A |
Absolute path traversal vulnerability in explorerdir.php in Frimousse 0.0.2 allows remote attackers to read arbitrary files and list arbitrary directories via a full pathname in the name parameter. | ||||
CVE-2008-0402 | 1 Ibm | 1 Websphere Business Modeler | 2024-11-21 | N/A |
Unspecified vulnerability in IBM WebSphere Business Modeler Basic and Advanced 6.0.2.1 before Interim Fix 11 allows remote authenticated users to bypass intended access restrictions and delete unspecified repository resources via unknown vectors, even when they are not administrators or members of the repository's owning group. | ||||
CVE-2008-0375 | 1 Oki Printing Solutions | 1 C5510 Mfp Printer | 2024-11-21 | N/A |
Unspecified vulnerability in OKI C5510MFP Printer CU H2.15, PU 01.03.01, System F/W 1.01, and Web Page 1.00 allows remote attackers to set the password and obtain administrative access via unspecified vectors. | ||||
CVE-2008-0372 | 1 8e6 | 1 R3000 Internet Filter | 2024-11-21 | N/A |
8e6 R3000 Internet Filter 2.0.05.33, and other versions before 2.0.11, allows remote attackers to bypass intended restrictions via a fragmented HTTP request. | ||||
CVE-2008-0350 | 1 Evilsentinel | 1 Evilsentinel | 2024-11-21 | N/A |
admin/index.php in Evilsentinel 1.0.9 and earlier sends a redirect to the web browser but does not exit, which allows remote attackers to gain administrative privileges and make arbitrary configuration changes. | ||||
CVE-2008-0329 | 1 Julien Plesniak | 1 Lulieblog | 2024-11-21 | N/A |
LulieBlog 1.0.1 and 1.0.2 does not restrict access to (1) article_suppr.php, (2) comment_accepter.php, and (3) comment_refuser.php in Admin/, which allows remote attackers to accept comments, delete comments, and delete articles via the id parameter. | ||||
CVE-2008-0293 | 1 Freeseat | 1 Freeseat | 2024-11-21 | N/A |
Unspecified vulnerability in cron.php in FreeSeat before 1.1.5d, when format.php has certain modifications, allows remote attackers to bypass authentication and gain privileges via unspecified vectors related to the show_foot function. | ||||
CVE-2008-0275 | 1 Drupal | 1 Atom Module | 2024-11-21 | N/A |
The Atom 4.7 before 4.7.x-1.0 and 5.x before 5.x-1.0 module for Drupal does not properly manage permissions for node (1) titles, (2) teasers, and (3) bodies, which might allow remote attackers to gain access to syndicated content. | ||||
CVE-2008-0246 | 1 Uploadscript | 2 Uploadimage, Uploadscript | 2024-11-21 | N/A |
admin.php in UploadScript 1.0 does not check for the original password before making a change to a new password, which allows remote attackers to gain administrator privileges via the pass parameter in a nopass (Set Password) action. | ||||
CVE-2008-0245 | 1 Uploadscript | 2 Uploadimage, Uploadscript | 2024-11-21 | N/A |
admin.php in UploadImage 1.0 does not check for the original password before making a change to a new password, which allows remote attackers to gain administrator privileges via the pass parameter in a nopass (Set Password) action. | ||||
CVE-2008-0233 | 1 Zero Cms | 1 Zero Cms | 2024-11-21 | N/A |
Unrestricted file upload vulnerability in Zero CMS 1.0 Alpha and earlier allows remote attackers to bypass intended access restrictions and upload and execute arbitrary files by uploading an avatar file with an accepted Content-Type such as image/jpeg. | ||||
CVE-2008-0217 | 1 Freebsd | 1 Freebsd | 2024-11-21 | N/A |
The script program in FreeBSD 5.0 through 7.0-PRERELEASE invokes openpty, which creates a pseudo-terminal with world-readable and world-writable permissions when it is not run as root, which allows local users to read data from the terminal of the user running script. | ||||
CVE-2008-0216 | 1 Freebsd | 1 Freebsd | 2024-11-21 | N/A |
The ptsname function in FreeBSD 6.0 through 7.0-PRERELEASE does not properly verify that a certain portion of a device name is associated with a pty of a user who is calling the pt_chown function, which might allow local users to read data from the pty from another user. | ||||
CVE-2008-0215 | 1 Hp | 2 Storage Essentials Srm Enterprise, Storage Essentials Srm Standard | 2024-11-21 | N/A |
Multiple unspecified vulnerabilities in HP Storage Essentials Storage Resource Management (SRM) before 6.0.0 allow remote attackers to obtain unspecified access to a managed device via unknown attack vectors. | ||||
CVE-2008-0214 | 1 Hp | 1 Select Identity | 2024-11-21 | N/A |
Multiple unspecified vulnerabilities in HP Select Identity 4.00, 4.01, 4.11, 4.12, 4.13, and 4.20 allow remote authenticated users to gain access via unknown vectors. | ||||
CVE-2008-0169 | 1 Ikiwiki | 1 Ikiwiki | 2024-11-21 | N/A |
Plugin/passwordauth.pm (aka the passwordauth plugin) in ikiwiki 1.34 through 2.47 allows remote attackers to bypass authentication, and login to any account for which an OpenID identity is configured and a password is not configured, by specifying an empty password during the login sequence. | ||||
CVE-2008-0162 | 2 Debian, Sam Lantinga | 2 Debian Linux, Splitvt | 2024-11-21 | N/A |
misc.c in splitvt 1.6.6 and earlier does not drop group privileges before executing xprop, which allows local users to gain privileges. | ||||
CVE-2008-0148 | 1 Tutos | 1 Tutos | 2024-11-21 | N/A |
TUTOS 1.3 does not restrict access to php/admin/cmd.php, which allows remote attackers to execute arbitrary shell commands via the cmd parameter in a direct request. |