|
CVE-2008-5720
|
Medium
|
2008-12-26
|
No exploit published
|
No public exploit
|
Cross-site scripting (XSS) vulnerability in Mayaa before 1.1.23 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving the default error page for the org.seasar.mayaa.impl.engine.PageNotFoundException exception and possibly other exceptions.
|
|
CVE-2008-1947
|
Medium
|
2008-06-04
|
No exploit published
|
No public exploit
|
Cross-site scripting (XSS) vulnerability in Apache Tomcat 5.5.9 through 5.5.26 and 6.0.0 through 6.0.16 allows remote attackers to inject arbitrary web script or HTML via the name parameter (aka the hostname attribute) to host-manager/html/add.
|
|
CVE-2008-1753
|
Medium
|
2008-04-11
|
No exploit published
|
No public exploit
|
Cross-site scripting (XSS) vulnerability in system/workplace/admin/workplace/sessions.jsp in Alkacon OpenCMS 7.0.3 allows remote attackers to inject arbitrary web script or HTML via the searchfilter parameter, a different vector than CVE-2008-1510.
|
|
CVE-2008-1728
|
Medium
|
2008-04-11
|
No exploit published
|
No public exploit
|
ConnectionManagerImpl.java in Ignite Realtime Openfire 3.4.5 allows remote authenticated users to cause a denial of service (daemon outage) by triggering large outgoing queues without reading messages.
|
|
CVE-2008-1285
|
Medium
|
2008-03-11
|
No exploit published
|
No public exploit
|
Cross-site scripting (XSS) vulnerability in Sun Java Server Faces (JSF) 1.2 before 1.2_08 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
|
|
CVE-2008-0002
|
Medium
|
2008-02-12
|
No exploit published
|
No public exploit
|
Apache Tomcat 6.0.0 through 6.0.15 processes parameters in the context of the wrong request when an exception occurs during parameter processing, which might allow remote attackers to obtain sensitive information, as demonstrated by disconnecting during this processing in order to trigger the exception.
|
|
CVE-2007-6286
|
Medium
|
2008-02-12
|
No exploit published
|
No public exploit
|
Apache Tomcat 5.5.11 through 5.5.25 and 6.0.0 through 6.0.15, when the native APR connector is used, does not properly handle an empty request to the SSL port, which allows remote attackers to trigger handling of "a duplicate copy of one of the recent requests," as demonstrated by using netcat to send the empty request.
|