Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2008-09-05 CVE-2008-3937 Cross-Site Scripting vulnerability in Opendb 1.0.6
Multiple cross-site scripting (XSS) vulnerabilities in Open Media Collectors Database (OpenDb) 1.0.6 allow remote attackers to inject arbitrary web script or HTML via the (1) user_id parameter in an edit action to user_admin.php, the (2) title parameter to listings.php, and the (3) redirect_url parameter to user_profile.php.
network
opendb CWE-79
4.3
2008-09-05 CVE-2008-3935 Cross-Site Scripting vulnerability in D-Ic Shop V50 and Shop V52
Cross-site scripting (XSS) vulnerability in DIC shop_v50 3.0 and earlier and shop_v52 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
d-ic CWE-79
4.3
2008-09-04 CVE-2008-3931 Link Following vulnerability in R Foundation R 2.7.2
javareconf in R 2.7.2 allows local users to overwrite arbitrary files via a symlink attack on temporary files.
6.9
2008-09-04 CVE-2008-3930 Link Following vulnerability in Debian Citadel Server 7.37
migrate_aliases.sh in Citadel Server 7.37 allows local users to overwrite arbitrary files via a symlink attack on a temporary file.
local
debian CWE-59
6.9
2008-09-04 CVE-2008-3928 Link Following vulnerability in Debian Honeyd Common 1.5
test.sh in Honeyd 1.5c might allow local users to overwrite arbitrary files via a symlink attack on a temporary file.
local
debian CWE-59
6.9
2008-09-04 CVE-2008-3926 Path Traversal vulnerability in Hans Oesterholt Cmme 1.12
Multiple directory traversal vulnerabilities in Content Management Made Easy (CMME) 1.12 allow remote attackers to (1) read arbitrary files via a ..
5.8
2008-09-04 CVE-2008-3925 Cross-Site Request Forgery (CSRF) vulnerability in Hans Oesterholt Cmme 1.12
Cross-site request forgery (CSRF) vulnerability in admin.php in Content Management Made Easy (CMME) 1.12 allows remote attackers to trigger the logout of an administrative user via a logout action.
4.3
2008-09-04 CVE-2008-3924 Permissions, Privileges, and Access Controls vulnerability in Hans Oesterholt Cmme 1.12
The "Make a backup" functionality in Content Management Made Easy (CMME) 1.12 stores sensitive information under the web root with insufficient access control, which allows remote attackers to discover (1) account names and (2) password hashes via a direct request for (a) backup/cmme_data.zip or (b) backup/cmme_cmme.zip.
4.3
2008-09-04 CVE-2008-3923 Cross-Site Scripting vulnerability in Hans Oesterholt Cmme 1.12
Multiple cross-site scripting (XSS) vulnerabilities in statistics.php in Content Management Made Easy (CMME) 1.12 allow remote attackers to inject arbitrary web script or HTML via the (1) page and (2) year parameters in an hstat_year action.
4.3
2008-09-04 CVE-2008-3921 Cross-Site Scripting vulnerability in Telartis BV Awstats Totals
Multiple cross-site scripting (XSS) vulnerabilities in AWStats Totals 1.0 through 1.14 allow remote attackers to inject arbitrary web script or HTML via the (1) month and (2) year parameter.
4.3