Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2009-03-20 CVE-2008-6498 Cross-Site Request Forgery (CSRF) vulnerability in Apachefriends Xampp 1.6.8
Cross-site request forgery (CSRF) vulnerability in security/xamppsecurity.php in XAMPP 1.6.8 allows remote attackers to hijack the authentication of users for requests that change a certain .htaccess password via the xampppasswd parameter.
6.8
2009-03-20 CVE-2008-6495 Cross-Site Scripting vulnerability in Zirkon BOX Yappa-Ng 2.3.2
Cross-site scripting (XSS) vulnerability in index.php in Fritz Berger yet another php photo album - next generation (yappa-ng) 2.3.2 allows remote attackers to inject arbitrary web script or HTML via the album parameter.
network
zirkon-box CWE-79
4.3
2009-03-20 CVE-2008-6494 Permissions, Privileges, and Access Controls vulnerability in Robs-Projects ASP User Engine.Net
ASP User Engine.NET stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for users.mdb.
network
low complexity
robs-projects CWE-264
5.0
2009-03-20 CVE-2008-6493 Permissions, Privileges, and Access Controls vulnerability in Easy-News Easy Content Management Publishing
Easy Content Management Publishing stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for Database/News.mdb.
network
low complexity
easy-news CWE-264
5.0
2009-03-20 CVE-2008-6492 Improper Input Validation vulnerability in Tizag Countdown Creator 3
Unrestricted file upload vulnerability in process.php in Tizag Countdown Creator 3 allows remote attackers to execute arbitrary code by uploading a file with an executable extension via index.php, then accessing the uploaded file via a direct request to the file in pics/.
network
tizag CWE-20
6.8
2009-03-19 CVE-2009-0971 Cross-Site Scripting vulnerability in Futomi Access Analyzer CGI
Cross-site scripting (XSS) vulnerability in futomi's CGI Cafe Access Analyzer CGI Standard Version 3.8.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
network
futomi CWE-79
4.3
2009-03-19 CVE-2009-0970 Code Injection vulnerability in PHPprobid PHP PRO BID 6.05
PHP remote file inclusion vulnerability in includes/class_image.php in PHP Pro Bid 6.05, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the fileExtension parameter.
network
phpprobid CWE-94
6.8
2009-03-19 CVE-2009-0969 Cross-Site Request Forgery (CSRF) vulnerability in PHPfox 1.6.2.1
Cross-site request forgery (CSRF) vulnerability in account/settings/account/index.php in phpFoX 1.6.21 allows remote attackers to hijack the authentication of administrators for requests that change the email address via the act[update] action.
network
phpfox CWE-352
6.8
2009-03-19 CVE-2009-0967 Resource Management Errors vulnerability in Solarwinds Serv-U File Server
The FTP server in Serv-U 7.0.0.1 through 7.4.0.1 allows remote authenticated users to cause a denial of service (service hang) via a large number of SMNT commands without an argument.
network
low complexity
solarwinds CWE-399
4.0
2009-03-19 CVE-2009-0661 Improper Input Validation vulnerability in Flashtux Weechat 0.2.6
Wee Enhanced Environment for Chat (WeeChat) 0.2.6 allows remote attackers to cause a denial of service (crash) via an IRC PRIVMSG command containing crafted color codes that trigger an out-of-bounds read.
network
low complexity
flashtux CWE-20
5.0