| |
Unrestricted file upload vulnerability in usercp.php in AlilG Application AliBoard Beta allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as an avatar, then accessing it via a direct request to the file in uploads/avatars/. |
2009-08-24 |
6.5 |
CVE-2008-7029
XF
BID
BUGTRAQ
OSVDB |
| adobe — coldfusion |
Multiple cross-site scripting (XSS) vulnerabilities in Adobe ColdFusion Server 8.0.1, 8, and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the startRow parameter to administrator/logviewer/searchlog.cfm, or the query string to (2) wizards/common/_logintowizard.cfm, (3) wizards/common/_authenticatewizarduser.cfm, or (4) administrator/enter.cfm. |
2009-08-18 |
4.3 |
CVE-2009-1872
CONFIRM |
| adobe — jrun |
Directory traversal vulnerability in logging/logviewer.jsp in the Management Console in Adobe JRun Application Server 4 Updater 7 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the logfile parameter. |
2009-08-18 |
4.0 |
CVE-2009-1873
CONFIRM |
| adobe — jrun |
Multiple cross-site scripting (XSS) vulnerabilities in the Management Console in Adobe JRun 4.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
2009-08-18 |
4.3 |
CVE-2009-1874
CONFIRM |
| adobe — coldfusion |
Multiple cross-site scripting (XSS) vulnerabilities in Adobe ColdFusion 8.0.1 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2009-1877. |
2009-08-18 |
4.3 |
CVE-2009-1875
CONFIRM |
| adobe — coldfusion |
Adobe ColdFusion 8.0.1 and earlier might allow attackers to obtain sensitive information via unspecified vectors, related to a “double-encoded null character vulnerability.” |
2009-08-18 |
5.0 |
CVE-2009-1876
CONFIRM |
| adobe — coldfusion |
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 8.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2009-1875. |
2009-08-18 |
4.3 |
CVE-2009-1877
CONFIRM |
| adobe — coldfusion |
Session fixation vulnerability in Adobe ColdFusion 8.0.1 and earlier allows remote attackers to hijack web sessions via unspecified vectors. |
2009-08-18 |
6.8 |
CVE-2009-1878
CONFIRM |
| arabless — saphplesson |
SQL injection vulnerability in admin/login.php in SaphpLesson 4.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the cp_username parameter, related to an error in the CleanVar function in includes/functions.php. |
2009-08-20 |
6.8 |
CVE-2009-2883
XF
BID
MILW0RM |
arzdev — gemini_lite
arzdev — gemini_portal |
admin.php in Arz Development The Gemini Portal 4.7 and earlier allows remote attackers to bypass authentication and gain administrator privileges by setting the user cookie to “admin” and setting the name parameter to “users.” |
2009-08-21 |
6.8 |
CVE-2008-7024
XF
BID
BUGTRAQ
MILW0RM
SECUNIA
OSVDB |
| availscript — jobs_portal_script |
Unrestricted file upload vulnerability in editlogo.php in AvailScript Jobs Portal Script allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as an image or logo, then accessing it via a direct request to the file in an unspecified directory. |
2009-08-21 |
6.5 |
CVE-2008-7021
XF
BID
MILW0RM
SECUNIA |
| baidu — baidu_hi_im |
NetService.dll in Baidu Hi IM allows remote servers to cause a denial of service (client crash) via a crafted login response that triggers a divide-by-zero error. |
2009-08-19 |
5.0 |
CVE-2008-7013
BUGTRAQ
OSVDB |
| bitmixsoft — php-lance |
Multiple directory traversal vulnerabilities in BitmixSoft PHP-Lance 1.52 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) language parameter to show.php and (2) in parameter to advanced_search.php. |
2009-08-21 |
5.0 |
CVE-2009-2923
MILW0RM |
| bzip — compress-raw-bzip2 |
Off-by-one error in the bzinflate function in Bzip2.xs in the Compress-Raw-Bzip2 module before 2.018 for Perl allows context-dependent attackers to cause a denial of service (application hang or crash) via a crafted bzip2 compressed stream that triggers a buffer overflow, a related issue to CVE-2009-1391. |
2009-08-19 |
4.3 |
CVE-2009-1884
CONFIRM
GENTOO |
| ca — host-based_intrusion_prevention_system |
kmxIds.sys before 7.3.1.18 in CA Host-Based Intrusion Prevention System (HIPS) 8.1 allows remote attackers to cause a denial of service (system crash) via a malformed packet. |
2009-08-19 |
5.0 |
CVE-2009-2740
CONFIRM |
| cacert — cacert |
Cross-site scripting (XSS) vulnerability in analyse.php in CAcert 20080921, and possibly other versions before 20080928, allows remote attackers to inject arbitrary web script or HTML via the CN (CommonName) field in the subject of an X.509 certificate. |
2009-08-21 |
4.3 |
CVE-2008-7017
XF
BID
MISC |
| checkpoint — zonealarm |
Buffer overflow in multiscan.exe in Check Point ZoneAlarm Security Suite 7.0.483.000 and 8.0.020.000 allows local users to execute arbitrary code via a file or directory with a long path. NOTE: some of these details are obtained from third party information. |
2009-08-19 |
6.9 |
CVE-2008-7009
XF
VUPEN
SECTRACK
BID
BUGTRAQ
SECUNIA
OSVDB |
| checkpoint — zonealarm |
TrueVector in Check Point ZoneAlarm 8.0.020.000, with vsmon.exe running, allows remote HTTP proxies to cause a denial of service (crash) and disable the HIDS module via a crafted response. |
2009-08-21 |
4.3 |
CVE-2008-7025
XF
BID
BUGTRAQ |
| cisco — ios_xr |
Cisco IOS XR 3.4.0 through 3.8.1 allows remote attackers to cause a denial of service (session reset) via a BGP UPDATE message with an invalid attribute, as demonstrated in the wild on 17 August 2009. |
2009-08-19 |
4.3 |
CVE-2009-2055
CISCO |
| datingpro — matchmaking |
Multiple cross-site scripting (XSS) vulnerabilities in PG MatchMaking allow remote attackers to inject arbitrary web script or HTML via the show parameter to (1) browse_ladies.php and (2) browse_men.php, the (3) gender parameter to search.php, and the (4) id parameter to services.php. |
2009-08-20 |
4.3 |
CVE-2009-2882
BID
SECUNIA
MISC |
| dd-wrt — dd-wrt |
Multiple cross-site request forgery (CSRF) vulnerabilities in apply.cgi in DD-WRT 24 sp2 allow remote attackers to hijack the authentication of administrators for requests that (1) execute arbitrary commands via the ping_ip parameter; (2) change the administrative credentials via the http_username and http_passwd parameters; (3) enable remote administration via the remote_management parameter; or (4) configure port forwarding via certain from, to, ip, and pro parameters. NOTE: This issue reportedly exists because of a “weak … anti-CSRF fix” implemented in 24 sp2. |
2009-08-14 |
6.8 |
CVE-2008-6975
BUGTRAQ
BUGTRAQ
BUGTRAQ
MILW0RM
MISC |
| devalcms — devalcms |
Cross-site scripting (XSS) vulnerability in index.php in devalcms 1.4a allows remote attackers to inject arbitrary web script or HTML via the currentpath parameter. |
2009-08-19 |
4.3 |
CVE-2008-6982
CONFIRM |
digital_extreme — pariah
epic_games — unreal_tournament
groove_games — warpath
human_head_studios — dead_mans_hand
red_mercury — shadow_ops
whiptail_interactive — postal |
The Unreal engine, as used in Unreal Tournament 3 1.3, Unreal Tournament 2003 and 2004, Dead Man’s Hand, Pariah, WarPath, Postal2, and Shadow Ops, allows remote authenticated users to cause a denial of service (server exit) via multiple file downloads from the server, which triggers an assertion failure when the Closing flag in UnChan.cpp is set. |
2009-08-19 |
4.0 |
CVE-2008-7011
BID
BUGTRAQ
OSVDB
FULLDISC |
| efrontlearning — efront |
Unrestricted file upload vulnerability in filesystem3.class.php in eFront 3.5.1 build 2710 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension as an avatar, then accessing it via a direct request to the file in (1) student/avatars/ or (2) professor/avatars/. |
2009-08-21 |
6.8 |
CVE-2008-7026
BID
CONFIRM |
| elkagroup — elkapax_cms |
Cross-site scripting (XSS) vulnerability in the Search feature in elka CMS (aka Elkapax) allows remote attackers to inject arbitrary web script or HTML via the q parameter to the default URI. |
2009-08-21 |
4.3 |
CVE-2009-2930
BUGTRAQ |
| elvinbts — elvinbts |
Multiple cross-site scripting (XSS) vulnerabilities in Elvin 1.2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) component and (2) priority parameters to buglist.php; and the (3) Username (4) E-mail, (5) Pass, and (6) Confirm pass fields to createaccount.php. |
2009-08-21 |
4.3 |
CVE-2009-2920
XF
MILW0RM |
epic_games — unreal_tournament
frontlines — fuel_of_war |
Unreal engine 3, as used in Unreal Tournament 3 1.3, Frontlines: Fuel of War 1.1.1, and other products, allows remote attackers to cause a denial of service (server exit) via a packet with a large length value that triggers a memory allocation failure. |
2009-08-19 |
5.0 |
CVE-2008-7015
XF
BID
BUGTRAQ
OSVDB
FULLDISC |
| ezphotogallery — ezphotogallery |
Multiple cross-site scripting (XSS) vulnerabilities in Easy Photo Gallery (aka Ezphotogallery) 2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) galleryid parameter to gallery.php, and the (2) size or (3) imageid parameters to show.php. |
2009-08-19 |
4.3 |
CVE-2008-6988
XF
BUGTRAQ
OSVDB
MILW0RM
SECUNIA |
| fhttpd — fhttpd |
fhttpd 0.4.2 allows remote attackers to cause a denial of service (crash) via an Authorization HTTP header with an invalid character after the Basic value. |
2009-08-19 |
5.0 |
CVE-2008-7014
XF
BID
MILW0RM |
| fullrevolution — aspwebalbum |
Cross-site scripting (XSS) vulnerability in album.asp in Full Revolution aspWebAlbum 3.2 allows remote attackers to inject arbitrary web script or HTML via the message parameter in a summary action. |
2009-08-19 |
4.3 |
CVE-2008-6977
XF
BID
MILW0RM
MILW0RM
SECUNIA |
| fullrevolution — aspwebalbum |
Unrestricted file upload vulnerability in Full Revolution aspWebAlbum 3.2 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in pics/, related to the uploadmedia action in album.asp. |
2009-08-19 |
6.8 |
CVE-2008-6978
XF
BID
MILW0RM
MILW0RM
SECUNIA
OSVDB |
| garagesalesjunkie — garagesales_script |
Cross-site scripting (XSS) vulnerability in visitor/view.php in GarageSales Script allows remote attackers to inject arbitrary web script or HTML via the key parameter. NOTE: some of these details are obtained from third party information. |
2009-08-14 |
4.3 |
CVE-2009-2778
XF
VUPEN
MILW0RM
SECUNIA |
| gelatocms — gelatocms |
Cross-site scripting (XSS) vulnerability in admin/comments.php in Gelato CMS 0.95 allows remote attackers to inject arbitrary web script or HTML via the content parameter in a comment. NOTE: some of these details are obtained from third party information. |
2009-08-24 |
4.3 |
CVE-2008-7039
XF
BID
MISC
OSVDB |
| google — chrome |
Integer underflow in net/base/escape.cc in chrome.dll in Google Chrome 0.2.149.27 allows remote attackers to cause a denial of service (browser crash) via a URI with an invalid handler followed by a “%” (percent) character, which triggers a buffer over-read, as demonstrated using an “about:%” URI. |
2009-08-19 |
4.3 |
CVE-2008-6995
XF |
| google — chrome |
Google Chrome BETA (0.2.149.27) does not prompt the user before saving an executable file, which makes it easier for remote attackers or malware to cause a denial of service (disk consumption) or exploit other vulnerabilities via a URL that references an executable file, possibly related to the “ask where to save each file before downloading” setting. |
2009-08-19 |
5.0 |
CVE-2008-6996
XF
BID
BUGTRAQ
BUGTRAQ
BUGTRAQ
BUGTRAQ
BUGTRAQ
BUGTRAQ
BUGTRAQ
OSVDB
MILW0RM
CONFIRM
CONFIRM |
| google — chrome |
Google Chrome 0.2.149.27 allows user-assisted remote attackers to cause a denial of service (browser crash) via an IMG tag with a long src attribute, which triggers the crash when the victim performs an “Inspect Element” action. |
2009-08-19 |
4.3 |
CVE-2008-6997
XF
BID
MILW0RM
OSVDB
MISC |
| hp — insight_control_suite_for_linux |
Cross-site request forgery (CSRF) vulnerability in HP Insight Control Suite For Linux (aka ICE-LX) before 2.11 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors. |
2009-08-14 |
6.8 |
CVE-2009-2677
HP
HP |
| hyperstop — web_host_directory |
HyperStop Web Host Directory 1.2 allows remote attackers to bypass authentication and download a database backup via a direct request to admin/backup/db. |
2009-08-19 |
5.0 |
CVE-2008-7008
XF
BID
SECUNIA
MISC
OSVDB |
| ibm — db2 |
Memory leak in the Security component in IBM DB2 8.1 before FP18 on Unix platforms allows attackers to cause a denial of service (memory consumption) via unspecified vectors, related to private memory within the DB2 memory structure. |
2009-08-19 |
5.0 |
CVE-2009-2858
CONFIRM |
| ibm — db2 |
IBM DB2 8.1 before FP18 allows attackers to obtain unspecified access via a das command. |
2009-08-19 |
4.6 |
CVE-2009-2859
VUPEN
CONFIRM |
| ibm — db2 |
Unspecified vulnerability in db2jds in IBM DB2 8.1 before FP18 allows remote attackers to cause a denial of service (service crash) via “malicious packets.” |
2009-08-19 |
5.0 |
CVE-2009-2860
VUPEN
CONFIRM |
linux — kernel
linux — kernel |
The load_flat_shared_library function in fs/binfmt_flat.c in the flat subsystem in the Linux kernel before 2.6.31-rc6 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by executing a shared flat binary, which triggers an access of an “uninitialized cred pointer.” |
2009-08-14 |
4.9 |
CVE-2009-2768
MLIST
CONFIRM
MLIST |
linux — kernel
linux — kernel |
The do_sigaltstack function in kernel/signal.c in Linux kernel 2.6 before 2.6.31-rc5, when running on 64-bit systems, does not clear certain padding bytes from a structure, which allows local users to obtain sensitive information from the kernel stack via the sigaltstack function. |
2009-08-18 |
4.9 |
CVE-2009-2847
CONFIRM
MLIST
MLIST |
| linux — kernel |
The execve function in the Linux kernel, possibly 2.6.30-rc6 and earlier, does not properly clear the current->clear_child_tid pointer, which allows local users to cause a denial of service (memory corruption) via a clone system call with CLONE_CHILD_SETTID or CLONE_CHILD_CLEARTID enabled, which is not properly handled during thread creation and exit. |
2009-08-18 |
4.7 |
CVE-2009-2848
MLIST
MLIST
MLIST |
| linux — kernel |
The md driver (drivers/md/md.c) in the Linux kernel before 2.6.30.2 might allow local users to cause a denial of service (NULL pointer dereference) via vectors related to “suspend_* sysfs attributes” and the (1) suspend_lo_store or (2) suspend_hi_store functions. NOTE: this is only a vulnerability when sysfs is writable by an attacker. |
2009-08-18 |
4.7 |
CVE-2009-2849
MISC
MLIST
MLIST
CONFIRM
CONFIRM |
| luke_mewburn — tnftpd |
tnftpd before 20080929 splits large command strings into multiple commands, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks via unknown vectors, probably involving a crafted ftp:// link to a tnftpd server. |
2009-08-21 |
6.8 |
CVE-2008-7016
XF
SECUNIA
OSVDB
CONFIRM |
| microtik — routeros |
MicroTik RouterOS 3.x through 3.13 and 2.x through 2.9.51 allows remote attackers to modify Network Management System (NMS) settings via a crafted SNMP set request. |
2009-08-19 |
6.4 |
CVE-2008-6976
XF
BID
MILW0RM |
| nashtech — easy_php_calendar |
Cross-site scripting (XSS) vulnerability in NashTech Easy PHP Calendar 6.3.25 allows remote attackers to inject arbitrary web script or HTML via the Details field (descr parameter) in an Add New Event action in an unspecified request as generated by an add action in index.php. |
2009-08-21 |
4.3 |
CVE-2008-7018
XF
BID
BUGTRAQ |
| natterchat — natterchat |
Multiple cross-site scripting (XSS) vulnerabilities in NatterChat 1.12 allow remote attackers to inject arbitrary web script or HTML via the (1) txtUsername parameter to registerDo.asp, as invoked from register.asp, or (2) txtRoomName parameter to room_new.asp. NOTE: these issues might be resultant from XSS in SQL error messages. |
2009-08-24 |
4.3 |
CVE-2008-7048
XF
OSVDB
FULLDISC |
| neon — neon |
neon before 0.28.6, when expat is used, does not properly detect recursion during entity expansion, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564. |
2009-08-21 |
4.3 |
CVE-2009-2473
FEDORA
FEDORA
SECUNIA
MLIST
MLIST |
| neon — neon |
neon before 0.28.6, when OpenSSL is used, does not properly handle a ‘\0′ character in a domain name in the subject’s Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408. |
2009-08-21 |
6.8 |
CVE-2009-2474
FEDORA
FEDORA
SECUNIA
MLIST
MLIST |
| ntop — ntop |
The checkHTTPpassword function in http.c in ntop 3.3.10 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an Authorization HTTP header that lacks a : (colon) character in the base64-decoded string. |
2009-08-21 |
5.0 |
CVE-2009-2732
VUPEN
BUGTRAQ
BUGTRAQ
SECUNIA |
| parallels — plesk |
Plesk 8.6.0, when short mail login names (SHORTNAMES) are enabled, allows remote attackers to bypass authentication and send spam e-mail via a message with (1) a base64-encoded username that begins with a valid shortname, or (2) a username that matches a valid password, as demonstrated using (a) SMTP and qmail, and (b) Courier IMAP and POP3. |
2009-08-19 |
5.8 |
CVE-2008-6984
XF
SECTRACK
BID
BUGTRAQ
OSVDB |
| phpadultsite — phpadultsite_cms |
Cross-site scripting (XSS) vulnerability in as_archives.php in phpAdultSite CMS, possibly 2.3.2, allows remote attackers to inject arbitrary web script or HTML via the results_per_page parameter to index.php. NOTE: some of these details are obtained from third party information. NOTE: this issue might be resultant from a separate SQL injection vulnerability. |
2009-08-19 |
4.3 |
CVE-2008-6979
XF
BID
BUGTRAQ
MISC
SECUNIA
OSVDB |
| phpadultsite — phpadultsite_cms |
index.php in phpAdultSite CMS, possibly 2.3.2, allows remote attackers to obtain the full installation path via an invalid results_per_page parameter, which leaks the path in an error message. NOTE: this issue might be resultant from a separate SQL injection vulnerability. |
2009-08-19 |
5.0 |
CVE-2008-6981
XF
BUGTRAQ
MISC |
| phpauction — phpauction |
phpAuction 3.2, and possibly 3.3.0 GPL Basic edition, allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function. |
2009-08-19 |
5.0 |
CVE-2008-6999
XF
SECUNIA
MISC
OSVDB |
| phpscriptsnow — world’s_tallest_buildings |
Cross-site scripting (XSS) vulnerability in bios.php in PHP Scripts Now World’s Tallest Buildings allows remote attackers to inject arbitrary web script or HTML via the rank parameter. |
2009-08-20 |
4.3 |
CVE-2009-2884
XF
OSVDB
SECUNIA
MISC |
| phpscriptsnow — president_bios |
Cross-site scripting (XSS) vulnerability in bios.php in PHP Scripts Now President Bios allows remote attackers to inject arbitrary web script or HTML via the rank parameter. |
2009-08-20 |
4.3 |
CVE-2009-2887
XF
SECUNIA
MISC |
| phpscriptsnow — hangman |
Cross-site scripting (XSS) vulnerability in index.php in PHP Scripts Now Hangman allows remote attackers to inject arbitrary web script or HTML via the letters parameter. |
2009-08-20 |
4.3 |
CVE-2009-2889
XF
OSVDB
SECUNIA
MISC |
| phpscriptsnow — riddles |
Cross-site scripting (XSS) vulnerability in results.php in PHP Scripts Now Riddles allows remote attackers to inject arbitrary web script or HTML via the searchquery parameter. |
2009-08-20 |
4.3 |
CVE-2009-2890
XF
OSVDB
SECUNIA
MISC |
| phpversion — php_vx_guestbook |
Free PHP VX Guestbook 1.06 allows remote attackers to bypass authentication and download a backup of the database via a direct request to admin/backupdb.php. |
2009-08-19 |
5.0 |
CVE-2008-7006
XF |
| reputation — reputation |
Directory traversal vulnerability in include/reputation/rep_profile.php in the Reputation plugin 2.2.4, 2.2.3, 2.0.4, and earlier for PunBB, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the pun_user[language] parameter. |
2009-08-17 |
6.8 |
CVE-2009-2787
XF
MILW0RM
SECUNIA
MISC
OSVDB |
| ryan.mcgeary — wp-syntax |
WP-Syntax plugin 0.9.1 and earlier for Wordpress, with register_globals enabled, allows remote attackers to execute arbitrary PHP code via the test_filter[wp_head] array parameter to test/index.php, which is used in a call to the call_user_func_array function. |
2009-08-18 |
6.8 |
CVE-2009-2852
XF
BID
MILW0RM |
| sap — netweaver |
Cross-site scripting (XSS) vulnerability in uddiclient/process in the UDDI client in SAP NetWeaver Application Server (Java) 7.0 allows remote attackers to inject arbitrary web script or HTML via the TModel Key field. |
2009-08-21 |
4.3 |
CVE-2009-2932
MISC
XF
SECTRACK
BID
BUGTRAQ
MISC
SECUNIA
OSVDB |
| simple_machines — phpraider |
Cross-site scripting (XSS) vulnerability in an unspecified component in Simple Machines phpRaider 1.0.7 allows remote attackers to inject arbitrary web script or HTML via the resistance field. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. |
2009-08-24 |
4.3 |
CVE-2008-7035
XF
BID |
| squid-cache — squid |
The strListGetItem function in src/HttpHeaderTools.c in Squid 2.7 allows remote attackers to cause a denial of service via a crafted auth header with certain comma delimiters that trigger an infinite loop of calls to the strcspn function. |
2009-08-18 |
5.0 |
CVE-2009-2855
MISC
MLIST
MLIST
MLIST
MISC
CONFIRM |
sun — opensolaris
sun — solaris |
The kernel in Sun Solaris 8, 9, and 10, and OpenSolaris before snv_103, does not properly handle interaction between the filesystem and virtual-memory implementations, which allows local users to cause a denial of service (deadlock and system halt) via vectors involving mmap and write operations on the same file. |
2009-08-19 |
4.9 |
CVE-2009-2857
SUNALERT
CONFIRM |
sun — opensolaris
sun — solaris |
The (1) sendfile and (2) sendfilev functions in Sun Solaris 8 through 10, and OpenSolaris before snv_110, allow local users to cause a denial of service (panic) via vectors related to vnode function calls. |
2009-08-21 |
4.9 |
CVE-2009-2912
SUNALERT
CONFIRM |
| tgs-cms — tgs_content_management |
Cross-site scripting (XSS) vulnerability in login.php in TGS Content Management 0.x allows remote attackers to inject arbitrary web script or HTML via the previous_page parameter, a different vector than CVE-2008-6839. |
2009-08-21 |
4.3 |
CVE-2009-2928
XF
MILW0RM |
| wordpress — wordpress |
Cross-site scripting (XSS) vulnerability in the administrator interface in WordPress before 2.8.2 allows remote attackers to inject arbitrary web script or HTML via a comment author URL. |
2009-08-18 |
4.3 |
CVE-2009-2851
CONFIRM |
| wordpress — wordpress |
Wordpress before 2.8.3 does not check capabilities for certain actions, which allows remote attackers to make unauthorized edits or additions via a direct request to (1) edit-comments.php, (2) edit-pages.php, (3) edit.php, (4) edit-category-form.php, (5) edit-link-category-form.php, (6) edit-tag-form.php, (7) export.php, (8) import.php, or (9) link-add.php in wp-admin/. |
2009-08-18 |
6.4 |
CVE-2009-2854
CONFIRM |
| xzeroscripts — xzero_community_classifieds |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in XZero Community Classifieds 4.97.8 allow remote attackers to inject arbitrary web script or HTML via (1) the postevent parameter in a post action or (2) the _xzcal_y parameter. |
2009-08-20 |
4.3 |
CVE-2009-2893
VUPEN
BID
SECUNIA
MISC |
| xzeroscripts — xzero_community_classifieds |
Cross-site scripting (XSS) vulnerability in index.php in XZero Community Classifieds 4.97.8 allows remote attackers to inject arbitrary web script or HTML via the URI. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. |
2009-08-21 |
4.3 |
CVE-2009-2913
SECUNIA |
| xzeroscripts — xzero_community_classifieds |
Cross-site scripting (XSS) vulnerability in index.php in XZero Community Classifieds 4.97.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the name of an uploaded file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. |
2009-08-21 |
4.3 |
CVE-2009-2914
VUPEN |
zen-cart — zen_cart
zen_cart — zen_cart |
Multiple SQL injection vulnerabilities in includes/classes/shopping_cart.php in Zen Cart 1.2.0 through 1.3.8a, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the id parameter when (1) adding or (2) updating the shopping cart. |
2009-08-19 |
6.8 |
CVE-2008-6985
CONFIRM
BID
BUGTRAQ
BUGTRAQ
OSVDB
MISC
SECUNIA |
| zen-cart — zen_cart |
SQL injection vulnerability in the actionMultipleAddProduct function in includes/classes/shopping_cart.php in Zen Cart 1.3.0 through 1.3.8a, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the products_id array parameter in a multiple_products_add_product action, a different vulnerability than CVE-2008-6985. |
2009-08-19 |
6.8 |
CVE-2008-6986
CONFIRM
BID
BUGTRAQ
BUGTRAQ
OSVDB
MISC
SECUNIA |