
CVE-2008-3937 – OpenDB 1.0.6 - 'listings.php?title' Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2008-3937
05 Sep 2008 — Multiple cross-site scripting (XSS) vulnerabilities in Open Media Collectors Database (OpenDb) 1.0.6 allow remote attackers to inject arbitrary web script or HTML via the (1) user_id parameter in an edit action to user_admin.php, the (2) title parameter to listings.php, and the (3) redirect_url parameter to user_profile.php. Múltiples vulnerabilidades de ejecución de secuencias de comandos en sitios cruzados (XSS) en Open Media Collectors Database (OpenDb) 1.0.6 permiten a atacantes remotos inyectar arbitra... • https://www.exploit-db.com/exploits/32314 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2008-3938
https://notcve.org/view.php?id=CVE-2008-3938
05 Sep 2008 — Cross-site request forgery (CSRF) vulnerability in user_admin.php in Open Media Collectors Database (OpenDb) 1.0.6 allows remote attackers to change arbitrary passwords via an update_password action. Vulnerabilidad de falsificación de petición en sitios cruzados (CSFR) de user_admin.php en Open Media Collectors Database (OpenDb) 1.0.6 permite a atacantes remotos cambiar arbitrariamente contraseñas mediante una acción update_password. • http://packetstorm.linuxsecurity.com/0808-exploits/omcd-xssxsrf.txt • CWE-352: Cross-Site Request Forgery (CSRF) •

CVE-2008-2020
https://notcve.org/view.php?id=CVE-2008-2020
30 Apr 2008 — The CAPTCHA implementation as used in (1) Francisco Burzi PHP-Nuke 7.0 and 8.1, (2) my123tkShop e-Commerce-Suite (aka 123tkShop) 0.9.1, (3) phpMyBitTorrent 1.2.2, (4) TorrentFlux 2.3, (5) e107 0.7.11, (6) WebZE 0.5.9, (7) Open Media Collectors Database (aka OpenDb) 1.5.0b4, and (8) Labgab 1.1 uses a code_bg.jpg background image and the PHP ImageString function in a way that produces an insufficient number of different images, which allows remote attackers to pass the CAPTCHA test via an automated attack usi... • http://securityreason.com/securityalert/3834 • CWE-330: Use of Insufficiently Random Values •