Browse Database

Browsing Vulnerabilities Disclosed in January of 2008

<< Back to Browse
OSVDB IDDisclosure DateTitle
56353 2008-01-26 WoltLab Burning Board index.php Private Message Deletion CSRF
40692 2008-01-26 F5 BIG-IP Application Security Manager rep_request.php report_type Parameter XSS
40818 2008-01-26 Simple Forum forum.php Multiple Parameter XSS
40768 2008-01-26 ASPired2Protect login.asp Multiple Parameter SQL Injection
40819 2008-01-26 Simple Forum thumbnail.php file Parameter Traversal Arbitrary File Access
41180 2008-01-26 Bubbling Library yui-menu.tpl.php uri Parameter Traversal Local File Inclusion
41181 2008-01-26 Bubbling Library simple.tpl.php uri Parameter Traversal Local File Inclusion
41182 2008-01-26 Bubbling Library advanced.tpl.php uri Parameter Traversal Local File Inclusion
41183 2008-01-26 Bubbling Library yui-menu.php page Parameter Traversal Local File Inclusion
41184 2008-01-26 Bubbling Library simple.php page Parameter Traversal Local File Inclusion
41185 2008-01-26 Bubbling Library advanced.php page Parameter Traversal Local File Inclusion
50969 2008-01-26 PhPress sql_phpress.php User Database Disclosure
42840 2008-01-25 UltraVNC vncviewer/ClientConnection.cpp ClientConnection::NegotiateProtocolVersion() vncviewer Remote Overflow
41153 2008-01-25 PatchLink Update Client for Unix rebootTask /tmp/plshutdown Symlink Arbitrary File Truncation
42838 2008-01-25 Xdg-utils xdg-open URL Argument Arbitrary Command Execution
42839 2008-01-25 Xdg-utils xdg-email URL Argument Arbitrary Command Execution
42536 2008-01-25 Mambo LaiThai Unspecified SQL Injection
43227 2008-01-25 General Electric (GE) Proficy Real-Time Information Portal Base64-Encoded Password Disclosure
40573 2008-01-25 metashell PATH Execution Unspecified Issue
40581 2008-01-25 Open WebMail (OWM) Multiple Unspecified XSS
40697 2008-01-25 CandyPress Store ajax/ajax_getTiers.asp idcust Parameter SQL Injection
40698 2008-01-25 CandyPress Store ajax/ajax_getCust.asp idcust Parameter SQL Injection
40699 2008-01-25 CandyPress Store ajax/ajax_getBrands.asp recid Parameter SQL Injection
40700 2008-01-25 CandyPress Store ajax/ajax_tableFields.asp tableName Parameter SQL Injection
40701 2008-01-25 CandyPress Store admin/utilities_ConfigHelp.asp helpfield Parameter SQL Injection
40702 2008-01-25 CandyPress Store admin/SA_shipFedExMeter.asp FedExAccount Parameter SQL Injection
40703 2008-01-25 CandyPress Store ajax/ajax_optInventory.asp Multiple Parameter SQL Injection
40704 2008-01-25 CandyPress Store admin/utilities_ConfigHelp.asp helpfield Parameter XSS
40762 2008-01-25 Persits Software XUpload Persits.XUpload.2 ActiveX (XUpload.ocx) AddFile() Method Overflow
41152 2008-01-25 PatchLink Update Client for Unix logtrimmer /tmp/patchlink.tmp Symlink Arbitrary File Truncation
40923 2008-01-25 Flinx category.php id Parameter SQL Injection
41168 2008-01-25 Sejoong Namo ActiveSquare6 Namo Web Editor NamoInstaller.NamoInstall ActiveX (NamoInstaller.dll) Install Method Arbitrary Code Execution
41559 2008-01-25 CandyPress admin/SA_shipFedExMeter.asp FedExAccount Variable Remote Path Disclosure
74525 2008-01-25 Bugzilla on Windows Uploaded Attachment Temporary File Local Information Disclosure
53477 2008-01-24 Movable Type Dynamic Error Template MTErrorMessage Tag XSS
42039 2008-01-24 ManageEngine Applications Manager jsp/ThresholdActionConfiguration.jsp Multiple Parameter XSS
42845 2008-01-24 Magnolia CE ActivationHandler Importing Permission Weakness Unspecified Issue
41333 2008-01-24 General Electric (GE) Fanuc Proficy Real-Time Information Portal Unrestricted File Upload Arbitrary Code Execution
53183 2008-01-24 Cisco PIX enable Special Character Handling Privilege Escalation
42041 2008-01-24 ManageEngine Applications Manager jsp/DiscoveryProfiles.jsp showlink Parameter XSS

The database information may change without any notice. Use of the information constitutes acceptance for use in an AS IS condition, and there are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the copyright holder or distributor (OSVDB or OSF) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

© Copyright 2002 - 2013 Open Source Vulnerability Database (OSVDB), All Rights Reserved.
Privacy Statement - Terms of Use