Browse Database

Browsing Vulnerabilities Disclosed in September of 2008

<< Back to Browse
OSVDB IDDisclosure DateTitle
48661 2008-09-30 Post Comments Script PostCommentsAdmin Cookie Admin Authentication Bypass
48634 2008-09-30 Autodesk Design Review DWF Viewer AdView.AdViewer.1 ActiveX (AdView.dll) SaveAs Method Arbitrary File Overwrite
48643 2008-09-30 moziloCMS download.php file Variable Traversal Arbitrary File Download
48640 2008-09-30 hyBook Guestbook Script hyBook.mdb Direct Request Information Disclosure
48644 2008-09-30 moziloCMS index.php page Variable Traversal Arbitrary File Download
48645 2008-09-30 moziloCMS index.php Multiple Variable XSS
48646 2008-09-30 moziloCMS download.php Multiple Variable XSS
48647 2008-09-30 moziloCMS gallery.php gal Variable XSS
48648 2008-09-30 moziloCMS admin/login.php URL XSS
48649 2008-09-30 moziloCMS Unspecified CSRF
48655 2008-09-30 Pritlog index.php filename Variable Traversal Remote File Access
48656 2008-09-30 GdPicture Pro Imaging SDK GdPicturePro5S.Imaging ActiveX (gdpicturepro5s.ocx) SaveAsPDF Method Arbitrary File Overwrite
48659 2008-09-30 FAQ Management Script index.php catid Variable SQL Injection
48657 2008-09-30 GdPicture Light Imaging Toolkit GdPicture4S.Imaging ActiveX (gdpicture4s.ocx) SaveAsPDF Method Arbitrary File Overwrite
48730 2008-09-30 Trend Micro OfficeScan OfficeScanNT Listener Traversal Arbitrary File Access
48687 2008-09-30 Celoxis user.do ni.smessage Variable XSS
48774 2008-09-30 Avaya CMS Solaris ACL for UFS File Systems NULL Deference Local DoS
48878 2008-09-30 Fedora Linux Kernel utrace Subsystem utrace_control Function Local DoS
48886 2008-09-30 lighttpd url.redirect / url.rewrite URL Decoding Remote Security Bypass
48889 2008-09-30 lighttpd mod_userdir Filename Component Case Mismatch Remote Access Restriction Bypass
48894 2008-09-30 libvirt xenstore /local/domain/ Subdirectory Xen Guest VM File Modification
48901 2008-09-30 Linux Kernel VMI arch/x86/kernel/vmi_32.c vmi_write_ldt_entry Function Crafted Function Calls Local DoS
49047 2008-09-30 LiveUpdate UpdateEngine ActiveX (LiveUpdate16.DLL) ApplyPatch Method Arbitrary Program Execution
49727 2008-09-30 KDE Konqueror Crafted URL-encoded String alert Function DoS
48755 2008-09-29 XAMPP adodb.php Multiple Variable XSS
48633 2008-09-29 PG MatchMaking Script news_read.php id Variable SQL Injection
48642 2008-09-29 Citrix XenApp Unspecified Local Privilege Escalation
48662 2008-09-29 MPlayer stream_read Function Crafted Video File Handling Multiple Underflows
48641 2008-09-29 HP Insight Diagnostics Unspecified Remote File Access
48635 2008-09-29 WordPress MU wp-admin/wpmu-blogs.php Multiple Variable XSS
48637 2008-09-29 tnftpd FTP Command Handling CSRF
48632 2008-09-29 PG MatchMaking Script gifts_show.php id Variable SQL Injection
48653 2008-09-29 A4Desk PHP Event Calendar index.php v Variable Remote File Inclusion
48753 2008-09-29 Blue Coat Security Gateway OS ICAP Patience Page URL XSS
48879 2008-09-29 Linux Kernel fs/splice.c generic_file_splice_write Function Inode Splice Local Privilege Escalation
49239 2008-09-29 ArabCMS rss.php rss Variable Traversal Local File Inclusion
49264 2008-09-29 Elxis CMS PHPSESSID Variable Session Fixation
49309 2008-09-29 PHP Jabbers Post Comment PostCommentsAdmin Cookie Manipulation Admin Authentication Bypass
49728 2008-09-29 Microsoft IE Crafted URL-encoded String alert Function DoS
49890 2008-09-29 JasPer libjasper/base/jas_stream.c jas_stream_printf Function Overflow

DONATE NOW!

User Status

Quick Searches

Advertisements

The database information may change without any notice. Use of the information constitutes acceptance for use in an AS IS condition, and there are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the copyright holder or distributor (OSVDB or OSF) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

© Copyright 2008 Open Source Vulnerability Database (OSVDB), All Rights Reserved.
Privacy Statement - Terms of Use