Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2009-03-20 CVE-2008-6500 Cross-Site Scripting vulnerability in Codetoad ASP Shopping Cart Script
Cross-site scripting (XSS) vulnerability in CodeToad ASP Shopping Cart Script allows remote attackers to inject arbitrary web script or HTML via the query string to the default URI.
network
codetoad CWE-79
4.3
2009-03-20 CVE-2009-1030 Cross-Site Scripting vulnerability in Wordpress MU
Cross-site scripting (XSS) vulnerability in the choose_primary_blog function in wp-includes/wpmu-functions.php in WordPress MU (WPMU) before 2.7 allows remote attackers to inject arbitrary web script or HTML via the HTTP Host header.
network
wordpress CWE-79
4.3
2009-03-20 CVE-2008-6499 Code Injection vulnerability in Apachefriends Xampp 1.6.8
security/xamppsecurity.php in XAMPP 1.6.8 performs an extract operation on the SERVER superglobal array, which allows remote attackers to spoof critical variables, as demonstrated by setting the REMOTE_ADDR variable to 127.0.0.1.
network
low complexity
apachefriends CWE-94
5.5
2009-03-20 CVE-2008-6498 Cross-Site Request Forgery (CSRF) vulnerability in Apachefriends Xampp 1.6.8
Cross-site request forgery (CSRF) vulnerability in security/xamppsecurity.php in XAMPP 1.6.8 allows remote attackers to hijack the authentication of users for requests that change a certain .htaccess password via the xampppasswd parameter.
6.8
2009-03-20 CVE-2008-6495 Cross-Site Scripting vulnerability in Zirkon BOX Yappa-Ng 2.3.2
Cross-site scripting (XSS) vulnerability in index.php in Fritz Berger yet another php photo album - next generation (yappa-ng) 2.3.2 allows remote attackers to inject arbitrary web script or HTML via the album parameter.
network
zirkon-box CWE-79
4.3
2009-03-20 CVE-2008-6494 Permissions, Privileges, and Access Controls vulnerability in Robs-Projects ASP User Engine.Net
ASP User Engine.NET stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for users.mdb.
network
low complexity
robs-projects CWE-264
5.0
2009-03-20 CVE-2008-6493 Permissions, Privileges, and Access Controls vulnerability in Easy-News Easy Content Management Publishing
Easy Content Management Publishing stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for Database/News.mdb.
network
low complexity
easy-news CWE-264
5.0
2009-03-20 CVE-2008-6492 Improper Input Validation vulnerability in Tizag Countdown Creator 3
Unrestricted file upload vulnerability in process.php in Tizag Countdown Creator 3 allows remote attackers to execute arbitrary code by uploading a file with an executable extension via index.php, then accessing the uploaded file via a direct request to the file in pics/.
network
tizag CWE-20
6.8
2009-03-19 CVE-2009-0971 Cross-Site Scripting vulnerability in Futomi Access Analyzer CGI
Cross-site scripting (XSS) vulnerability in futomi's CGI Cafe Access Analyzer CGI Standard Version 3.8.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
network
futomi CWE-79
4.3
2009-03-19 CVE-2009-0970 Code Injection vulnerability in PHPprobid PHP PRO BID 6.05
PHP remote file inclusion vulnerability in includes/class_image.php in PHP Pro Bid 6.05, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the fileExtension parameter.
network
phpprobid CWE-94
6.8