Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2009-09-14 CVE-2008-7226 SQL Injection vulnerability in PHP-Nuke Recipe Module 1.3/1.4
SQL injection vulnerability in index.php in the Recipes module 1.3, 1.4, and possibly other versions for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the recipeid parameter.
network
low complexity
php-nuke phpnuke CWE-89
7.5
2009-09-14 CVE-2008-7225 Buffer Errors vulnerability in Foxitsoftware WAC Server 2.0
Heap-based buffer overflow in Foxit Remote Access Server (aka WAC Server) 2.0 Build 3503 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long SSH packets, a different vulnerability than CVE-2008-0151.
network
low complexity
foxitsoftware CWE-119
critical
10.0
2009-09-14 CVE-2008-7224 Buffer Errors vulnerability in Elinks 0.11.1/0.11.11/0.11.2
Buffer overflow in entity_cache in ELinks before 0.11.4rc0 allows remote attackers to cause a denial of service (crash) via a crafted link.
network
low complexity
elinks CWE-119
7.8
2009-09-14 CVE-2008-7223 Cross-Site Scripting vulnerability in Linpha
Multiple cross-site scripting (XSS) vulnerabilities in LinPHA before 1.3.3 allow remote attackers to inject arbitrary web script or HTML via (1) ftp/index.php, (2) viewer.php, (3) functions/other.php, (4) include/left_menu.class.php, or (5) plugins/stats/stats_view.php.
network
linpha CWE-79
4.3
2009-09-14 CVE-2008-7222 Cross-Site Scripting vulnerability in Runcms 1.6.1
Cross-site scripting (XSS) vulnerability in system/admin.php in RunCMS 1.6.1 allows remote attackers to inject arbitrary web script or HTML via the rank_title parameter in a RankForumAdd action.
network
runcms CWE-79
4.3
2009-09-14 CVE-2008-7221 Cross-Site Request Forgery (CSRF) vulnerability in Runcms 1.6.1
Cross-site request forgery (CSRF) vulnerability in RunCMS 1.6.1 allows remote attackers to hijack the authentication of administrators for requests that (1) add new administrators or (2) modify user profiles via a crafted request to system/admin.php.
network
runcms CWE-352
6.8
2009-09-13 CVE-2008-7219 Permissions, Privileges, and Access Controls vulnerability in Horde products
Horde Kronolith H3 2.1 before 2.1.7 and 2.2 before 2.2-RC2; Nag H3 2.1 before 2.1.4 and 2.2 before 2.2-RC2; Mnemo H3 2.1 before 2.1.2 and H3 2.2 before 2.2-RC2; Groupware 1.0 before 1.0.3 and 1.1 before 1.1-RC2; and Groupware Webmail Edition 1.0 before 1.0.4 and 1.1 before 1.1-RC2 does not validate ownership when performing share changes, which has unknown impact and attack vectors.
network
low complexity
horde CWE-264
critical
10.0
2009-09-13 CVE-2008-7218 Security Bypass vulnerability in Horde Products
Unspecified vulnerability in the Horde API in Horde 3.1 before 3.1.6 and 3.2 before 3.2 before 3.2-RC2; Turba H3 2.1 before 2.1.6 and 2.2 before 2.2-RC2; Kronolith H3 2.1 before 2.1.7 and H3 2.2 before 2.2-RC2; Nag H3 2.1 before 2.1.4 and 2.2 before 2.2-RC2; Mnemo H3 2.1 before 2.1.2 and 2.2 before 2.2-RC2; Horde Groupware 1.0 before 1.0.3 and 1.1 before 1.1-RC2; and Groupware Webmail Edition 1.0 before 1.0.4 and 1.1 before 1.1-RC2 has unknown impact and attack vectors.
network
low complexity
horde
critical
10.0
2009-09-13 CVE-2007-6732 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Claudio Matsuoka Extended Module Player
Multiple buffer overflows in the dtt_load function in loaders/dtt_load.c Extended Module Player (XMP) 2.5.1 and earlier allow remote attackers to execute arbitrary code via unspecified vectors related to an untrusted length value and the (1) pofs and (2) plen arrays.
network
low complexity
claudio-matsuoka CWE-119
critical
10.0
2009-09-13 CVE-2007-6731 Code Injection vulnerability in Claudio Matsuoka Extended Module Player
Extended Module Player (XMP) 2.5.1 and earlier allow remote attackers to execute arbitrary code via an OXM file with a negative value, which bypasses a check in (1) test_oxm and (2) decrunch_oxm functions in misc/oxm.c, leading to a buffer overflow.
network
low complexity
claudio-matsuoka CWE-94
critical
10.0