Total
3371 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2008-5042 | 1 Zeeways | 1 Photovideotube | 2024-11-21 | 7.5 HIGH | N/A |
Zeeways PhotoVideoTube 1.1 and earlier allows remote attackers to bypass authentication and perform administrative tasks via a direct request to admin/home.php. | |||||
CVE-2008-5040 | 1 Graphiks | 1 Myforum | 2024-11-21 | 7.5 HIGH | N/A |
Graphiks MyForum 1.3 allows remote attackers to bypass authentication and gain administrative access by setting the (1) myforum_login and (2) myforum_pass cookies to 1. | |||||
CVE-2008-5022 | 3 Canonical, Debian, Mozilla | 5 Ubuntu Linux, Debian Linux, Firefox and 2 more | 2024-11-21 | 7.5 HIGH | N/A |
The nsXMLHttpRequest::NotifyEventListeners method in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to bypass the same-origin policy and execute arbitrary script via multiple listeners, which bypass the inner window check. | |||||
CVE-2008-4784 | 1 Aflog | 1 Aflog | 2024-11-21 | 7.5 HIGH | N/A |
aflog 1.01 allows remote attackers to bypass authentication and gain administrative access by setting the aflog_auth_a cookie to "A" or "O" in (1) edit_delete.php, (2) edit_cat.php, (3) edit_lock.php, and (4) edit_form.php. | |||||
CVE-2008-4783 | 1 Easy-script | 1 Tlads | 2024-11-21 | 7.5 HIGH | N/A |
tlAds 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the tlAds_login cookie to "admin." | |||||
CVE-2008-4752 | 1 Tech Logic | 1 Tlnews | 2024-11-21 | 7.5 HIGH | N/A |
TlNews 2.2 allows remote attackers to bypass authentication and gain administrative access by setting the tlNews_login cookie to admin. | |||||
CVE-2008-4722 | 1 Sun | 37 Blade 6000 Modular System With Chassis, Blade 6048 Modular System With Chassis, Blade 8000 Modular System and 34 more | 2024-11-21 | 9.0 HIGH | N/A |
Unspecified vulnerability in Sun Integrated Lights-Out Manager (ILOM) 2.0.1.5 through 2.0.4.26 allows remote authenticated users to (1) access the service processor (SP) and cause a denial of service (shutdown or reboot), or (2) access the host operating system and have an unspecified impact, via unknown vectors. | |||||
CVE-2008-4721 | 1 Php Jabbers | 1 Post Comment | 2024-11-21 | 7.5 HIGH | N/A |
PHP Jabbers Post Comment 3.0 allows remote attackers to bypass authentication and gain administrative access by setting the PostCommentsAdmin cookie to "logged." | |||||
CVE-2008-4714 | 1 Atomic Photo Album | 1 Atomic Photo Album | 2024-11-21 | 7.5 HIGH | N/A |
Atomic Photo Album 1.1.0 pre4 does not properly handle the apa_cookie_login and apa_cookie_password cookies, which probably allows remote attackers to bypass authentication and gain administrative access via modified cookies. | |||||
CVE-2008-4708 | 1 Sylvain Pasquet | 1 Bbzl.php | 2024-11-21 | 7.5 HIGH | N/A |
BbZL.PhP 0.92 allows remote attackers to bypass authentication and gain administrative access by setting the phorum_admin_session cookie to 1. | |||||
CVE-2008-4689 | 1 Mantis | 1 Mantis | 2024-11-21 | 7.5 HIGH | N/A |
Mantis before 1.1.3 does not unset the session cookie during logout, which makes it easier for remote attackers to hijack sessions. | |||||
CVE-2008-4679 | 1 Ibm | 1 Websphere Application Server | 2024-11-21 | 6.8 MEDIUM | N/A |
The Web Services Security component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.31 and 6.1 before 6.1.0.19, when Certificate Store Collections is configured to use Certificate Revocation Lists (CRL), does not call the setRevocationEnabled method on the PKIXBuilderParameters object, which prevents the "Java security method" from checking the revocation status of X.509 certificates and allows remote attackers to bypass intended access restrictions via a SOAP message with a revoked certificate. | |||||
CVE-2008-4649 | 1 Elxis | 1 Elxis Cms | 2024-11-21 | 7.5 HIGH | N/A |
Session fixation vulnerability in Elxis CMS 2008.1 revision 2204 allows remote attackers to hijack web sessions by setting the PHPSESSID parameter. | |||||
CVE-2008-4622 | 1 Phpfastnews | 1 Phpfastnews | 2024-11-21 | 7.5 HIGH | N/A |
The isLoggedIn function in fastnews-code.php in phpFastNews 1.0.0 allows remote attackers to bypass authentication and gain administrative access by setting the fn-loggedin cookie to 1. | |||||
CVE-2008-4614 | 1 Portalapp | 1 Portalapp | 2024-11-21 | 7.5 HIGH | N/A |
PortalApp 4.0 does not require authentication for (1) forums.asp and (2) content.asp, which allows remote attackers to create and delete forums, topics, and replies. | |||||
CVE-2008-4576 | 1 Linux | 1 Linux Kernel | 2024-11-21 | 7.8 HIGH | N/A |
sctp in Linux kernel before 2.6.25.18 allows remote attackers to cause a denial of service (OOPS) via an INIT-ACK that states the peer does not support AUTH, which causes the sctp_process_init function to clean up active transports and triggers the OOPS when the T1-Init timer expires. | |||||
CVE-2008-4515 | 1 Blue Coat Systems | 1 K9 Web Protection | 2024-11-21 | 7.5 HIGH | N/A |
Blue Coat K9 Web Protection 4.0.230 Beta relies on client-side JavaScript as a protection mechanism, which allows remote attackers to bypass authentication and access the (1) summary, (2) detail, (3) overrides, and (4) pwemail pages by disabling JavaScript. | |||||
CVE-2008-4427 | 1 Phlatline | 1 Personal Information Manager | 2024-11-21 | 7.5 HIGH | N/A |
changepassword.php in Phlatline's Personal Information Manager (pPIM) 1.0 and earlier does not require administrative authentication, which allows remote attackers to change arbitrary passwords. | |||||
CVE-2008-4389 | 1 Symantec | 2 Appstream, Workspace Streaming | 2024-11-21 | 9.3 HIGH | N/A |
Symantec AppStream 5.2.x and Symantec Workspace Streaming (SWS) 6.1.x before 6.1 SP4 do not properly perform authentication, which allows remote Workspace Streaming servers and man-in-the-middle attackers to download arbitrary executable files onto a client system, and execute these files, via unspecified vectors. | |||||
CVE-2008-4319 | 1 Libra File Manager | 1 Php Filemanager | 2024-11-21 | 6.4 MEDIUM | N/A |
fileadmin.php in Libra File Manager (aka Libra PHP File Manager) 1.18 and earlier allows remote attackers to bypass authentication, and read arbitrary files, modify arbitrary files, and list arbitrary directories, by inserting certain user and isadmin parameters in the query string. |