CVE-2008-7086 – Maian Greetings 2.1 - Insecure Cookie Handling
https://notcve.org/view.php?id=CVE-2008-7086
Maian Greetings 2.1 allows remote attackers to bypass authentication and gain administrative privileges by setting the mecard_admin_cookie cookie to admin. Maian Greetings v2,1 permite a atacantes remotos evitar la autenticación y obtener privilegios administrativos estableciendo la cookie mecard_admin_cookie a admin. • https://www.exploit-db.com/exploits/6050 http://www.securityfocus.com/bid/30199 https://exchange.xforce.ibmcloud.com/vulnerabilities/43744 • CWE-287: Improper Authentication •
CVE-2008-2209
https://notcve.org/view.php?id=CVE-2008-2209
Multiple cross-site scripting (XSS) vulnerabilities in admin/inc/header.php in Maian Greeting 2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) msg_script and (2) msg_script2 parameters. Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en admin/inc/header.php de Maian Greeting 2.1 permiten a atacantes remotos inyectar secuencias de comandos web o HTML mediante los parámetros 1) msg_script y (2) msg_script2. • http://secunia.com/advisories/30069 http://securityreason.com/securityalert/3887 http://www.securityfocus.com/archive/1/491582/100/0/threaded http://www.securityfocus.com/bid/29032 https://exchange.xforce.ibmcloud.com/vulnerabilities/42200 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2008-2213
https://notcve.org/view.php?id=CVE-2008-2213
Multiple cross-site scripting (XSS) vulnerabilities in admin/inc/footer.php in Maian Links 3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) msg_script2 and (2) msg_script3 parameters. Múltiples vulnerabilidades de ejecución de comandos en sitios cruzados en admin/inc/footer.php en Maian Links 3.1 permite a atacantes remotos inyectar secuencias de comandos web o HTML de su elección a través de los parámetros (1) msg_script2 y (2) msg_script3. • http://secunia.com/advisories/30065 http://securityreason.com/securityalert/3892 http://www.securityfocus.com/archive/1/491591/100/0/threaded http://www.securityfocus.com/bid/29032 https://exchange.xforce.ibmcloud.com/vulnerabilities/42208 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2008-2207
https://notcve.org/view.php?id=CVE-2008-2207
Cross-site scripting (XSS) vulnerability in admin/index.php in Maian Gallery 2.0 allows remote attackers to inject arbitrary web script or HTML via the keywords parameter in a search action. Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en admin/index.php de Maian Gallery 2.0 permite a atacantes remotos inyectar secuencias de comandos web o HTML mediante el parámetro keywords en una acción search. • http://secunia.com/advisories/30070 http://securityreason.com/securityalert/3885 http://www.securityfocus.com/archive/1/491583/100/0/threaded http://www.securityfocus.com/bid/29032 https://exchange.xforce.ibmcloud.com/vulnerabilities/42195 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2008-2206
https://notcve.org/view.php?id=CVE-2008-2206
Multiple cross-site scripting (XSS) vulnerabilities in Maian Music 1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) keywords parameter in a search action to index.php, and the (2) msg_script parameter to admin/inc/footer.php. Múltiples vulnerabilidades de ejecución de comandos en sitios cruzados en Maian Music 1.1 permiten a atacantes remotos inyectar secuencias de comandos Web o HTML de su elección a través de (1) el parámetro keywords en una acción de búsqueda en index.php, y de (2)el parámetro msg_script de admin/inc/footer.php. • http://secunia.com/advisories/30066 http://securityreason.com/securityalert/3884 http://www.securityfocus.com/archive/1/491590/100/0/threaded http://www.securityfocus.com/bid/29032 https://exchange.xforce.ibmcloud.com/vulnerabilities/42210 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •