<?xml version='1.0' encoding='UTF-8'?>
<nvd xmlns:vuln="http://scap.nist.gov/schema/vulnerability/0.4" xmlns:cpe-lang="http://cpe.mitre.org/language/2.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:cvss="http://scap.nist.gov/schema/cvss-v2/0.2" xmlns="http://scap.nist.gov/schema/feed/vulnerability/2.0" nvd_xml_version="2.0" pub_date="2009-11-23T03:10:00" xsi:schemaLocation="http://scap.nist.gov/schema/feed/vulnerability/2.0 http://nvd.nist.gov/schema/nvd-cve-feed_2.0.xsd">
    <entry id="CVE-2008-0061">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.00" />
                <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.01" />
                <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.02" />
                <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.03" />
                <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.04" />
                <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.05" />
                <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.06" />
                <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.07" />
                <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.08" />
                <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.09" />
                <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.10" />
                <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.11" />
                <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.12" />
                <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.13" />
                <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.14" />
                <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.15" />
                <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.16" />
                <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.17" />
                <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.18" />
                <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.19" />
                <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.20" />
                <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.21" />
                <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.22" />
                <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.23" />
                <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.24" />
                <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.25" />
                <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.26" />
                <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.27" />
                <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.28" />
                <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.29" />
                <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.30" />
                <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.31" />
                <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.32" />
                <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.33" />
                <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.34" />
                <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.35" />
                <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.36" />
                <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.37" />
                <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.38" />
                <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.39" />
                <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.2.12.01" />
                <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.2.12.02" />
                <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.2.12.03" />
                <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.2.12.04" />
                <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.2.12.05" />
                <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.2.12.06" />
                <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.2.12.07" />
                <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.3.01" />
                <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.3.02" />
                <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.3.03" />
                <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.3.04" />
                <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.3.05" />
                <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.3.06" />
                <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.3.07" />
                <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.3.07.01" />
                <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.3.07.02" />
                <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.3.07.03" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:maradns:maradns:1.3.07</vuln:product>
            <vuln:product>cpe:/a:maradns:maradns:1.3.06</vuln:product>
            <vuln:product>cpe:/a:maradns:maradns:1.0.00</vuln:product>
            <vuln:product>cpe:/a:maradns:maradns:1.0.01</vuln:product>
            <vuln:product>cpe:/a:maradns:maradns:1.0.02</vuln:product>
            <vuln:product>cpe:/a:maradns:maradns:1.0.04</vuln:product>
            <vuln:product>cpe:/a:maradns:maradns:1.0.03</vuln:product>
            <vuln:product>cpe:/a:maradns:maradns:1.3.07.01</vuln:product>
            <vuln:product>cpe:/a:maradns:maradns:1.0.06</vuln:product>
            <vuln:product>cpe:/a:maradns:maradns:1.3.07.02</vuln:product>
            <vuln:product>cpe:/a:maradns:maradns:1.0.05</vuln:product>
            <vuln:product>cpe:/a:maradns:maradns:1.3.07.03</vuln:product>
            <vuln:product>cpe:/a:maradns:maradns:1.0.08</vuln:product>
            <vuln:product>cpe:/a:maradns:maradns:1.0.07</vuln:product>
            <vuln:product>cpe:/a:maradns:maradns:1.0.09</vuln:product>
            <vuln:product>cpe:/a:maradns:maradns:1.3.01</vuln:product>
            <vuln:product>cpe:/a:maradns:maradns:1.3.02</vuln:product>
            <vuln:product>cpe:/a:maradns:maradns:1.3.03</vuln:product>
            <vuln:product>cpe:/a:maradns:maradns:1.3.04</vuln:product>
            <vuln:product>cpe:/a:maradns:maradns:1.3.05</vuln:product>
            <vuln:product>cpe:/a:maradns:maradns:1.0.12</vuln:product>
            <vuln:product>cpe:/a:maradns:maradns:1.0.13</vuln:product>
            <vuln:product>cpe:/a:maradns:maradns:1.0.10</vuln:product>
            <vuln:product>cpe:/a:maradns:maradns:1.0.11</vuln:product>
            <vuln:product>cpe:/a:maradns:maradns:1.0.17</vuln:product>
            <vuln:product>cpe:/a:maradns:maradns:1.0.16</vuln:product>
            <vuln:product>cpe:/a:maradns:maradns:1.0.15</vuln:product>
            <vuln:product>cpe:/a:maradns:maradns:1.0.14</vuln:product>
            <vuln:product>cpe:/a:maradns:maradns:1.0.19</vuln:product>
            <vuln:product>cpe:/a:maradns:maradns:1.0.18</vuln:product>
            <vuln:product>cpe:/a:maradns:maradns:1.2.12.05</vuln:product>
            <vuln:product>cpe:/a:maradns:maradns:1.2.12.04</vuln:product>
            <vuln:product>cpe:/a:maradns:maradns:1.2.12.03</vuln:product>
            <vuln:product>cpe:/a:maradns:maradns:1.2.12.02</vuln:product>
            <vuln:product>cpe:/a:maradns:maradns:1.2.12.07</vuln:product>
            <vuln:product>cpe:/a:maradns:maradns:1.2.12.06</vuln:product>
            <vuln:product>cpe:/a:maradns:maradns:1.0.29</vuln:product>
            <vuln:product>cpe:/a:maradns:maradns:1.0.27</vuln:product>
            <vuln:product>cpe:/a:maradns:maradns:1.2.12.01</vuln:product>
            <vuln:product>cpe:/a:maradns:maradns:1.0.28</vuln:product>
            <vuln:product>cpe:/a:maradns:maradns:1.0.25</vuln:product>
            <vuln:product>cpe:/a:maradns:maradns:1.0.26</vuln:product>
            <vuln:product>cpe:/a:maradns:maradns:1.0.24</vuln:product>
            <vuln:product>cpe:/a:maradns:maradns:1.0.23</vuln:product>
            <vuln:product>cpe:/a:maradns:maradns:1.0.22</vuln:product>
            <vuln:product>cpe:/a:maradns:maradns:1.0.21</vuln:product>
            <vuln:product>cpe:/a:maradns:maradns:1.0.20</vuln:product>
            <vuln:product>cpe:/a:maradns:maradns:1.0.36</vuln:product>
            <vuln:product>cpe:/a:maradns:maradns:1.0.37</vuln:product>
            <vuln:product>cpe:/a:maradns:maradns:1.0.38</vuln:product>
            <vuln:product>cpe:/a:maradns:maradns:1.0.39</vuln:product>
            <vuln:product>cpe:/a:maradns:maradns:1.0.33</vuln:product>
            <vuln:product>cpe:/a:maradns:maradns:1.0.32</vuln:product>
            <vuln:product>cpe:/a:maradns:maradns:1.0.35</vuln:product>
            <vuln:product>cpe:/a:maradns:maradns:1.0.34</vuln:product>
            <vuln:product>cpe:/a:maradns:maradns:1.0.31</vuln:product>
            <vuln:product>cpe:/a:maradns:maradns:1.0.30</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0061</vuln:cve-id>
        <vuln:published-datetime>2008-01-03T17:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:06.717-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-04T08:44:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.maradns.org/changelog.html">http://www.maradns.org/changelog.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://maradns.blogspot.com/2007/08/maradns-update-all-versions.html">http://maradns.blogspot.com/2007/08/maradns-update-all-versions.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27124">27124</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/0026">ADV-2008-0026</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2008/dsa-1445">DSA-1445</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://security.gentoo.org/glsa/glsa-200801-16.xml">GLSA-200801-16</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28650">28650</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28334">28334</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28329">28329</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://bugs.gentoo.org/show_bug.cgi?id=204351">http://bugs.gentoo.org/show_bug.cgi?id=204351</vuln:reference>
        </vuln:references>
        <vuln:summary>MaraDNS 1.0 before 1.0.41, 1.2 before 1.2.12.08, and 1.3 before 1.3.07.04 allows remote attackers to cause a denial of service via a crafted DNS packet that prevents an authoritative name (CNAME) record from resolving, aka "improper rotation of resource records."</vuln:summary>
    </entry>
    <entry id="CVE-2008-0089">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:clip-share:clipshare" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:clip-share:clipshare</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0089</vuln:cve-id>
        <vuln:published-datetime>2008-01-03T20:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-09-11T01:17:31.250-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-04T13:31:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-89" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27108">27108</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/4830">4830</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28313">28313</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://osvdb.org/40077">40077</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39364">clipshare-uprofile-sql-injection(39364)</vuln:reference>
        </vuln:references>
        <vuln:summary>SQL injection vulnerability in uprofile.php in ClipShare allows remote attackers to execute arbitrary SQL commands via the UID parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0090">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:divx:divx_player:6.6.0" />
                <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:7" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:microsoft:ie:7</vuln:product>
            <vuln:product>cpe:/a:divx:divx_player:6.6.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0090</vuln:cve-id>
        <vuln:published-datetime>2008-01-03T20:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:11.420-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-04T13:34:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-119" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27106">27106</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/4829">4829</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39386">divxwebplayer-npUpload-dos(39386)</vuln:reference>
        </vuln:references>
        <vuln:summary>A certain ActiveX control in npUpload.dll in DivX Player 6.6.0 allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long argument to the SetPassword method.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0091">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:agency4net:webftp:1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:agency4net:webftp:1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0091</vuln:cve-id>
        <vuln:published-datetime>2008-01-03T20:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:11.577-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>6.4</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-04T13:41:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-22" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27092">27092</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/4828">4828</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VIM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.attrition.org/pipermail/vim/2008-January/001865.html">20080104 true: AGENCY4NET WEBFTP directory traversal; deletion possible</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39343">agency4net-download2-directory-traversal(39343)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/0051">ADV-2008-0051</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28309">28309</vuln:reference>
        </vuln:references>
        <vuln:summary>Directory traversal vulnerability in download2.php in AGENCY4NET WEBFTP 1 allows remote attackers to read and delete arbitrary files via a .. (dot dot) in the file parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0092">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:phpwebsite:phpwebsite:1.4.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:phpwebsite:phpwebsite:1.4.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0092</vuln:cve-id>
        <vuln:published-datetime>2008-01-03T20:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:11.717-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-04T13:51:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-79" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27090">27090</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/485704/100/0/threaded">20080101 Cross-Site Scripting (XSS) in phpWebSite 1.4.0 search</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://phpwebsite.appstate.edu/blog/2143">http://phpwebsite.appstate.edu/blog/2143</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39391">phpwebsite-search-xss(39391)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/3511">3511</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28303">28303</vuln:reference>
        </vuln:references>
        <vuln:summary>Cross-site scripting (XSS) vulnerability in index.php in the search module in Appalachian State University phpWebSite 1.4.0 allows remote attackers to inject arbitrary web script or HTML via the search parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0093">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:eticket:eticket:1.5.5.2" />
                <cpe-lang:fact-ref name="cpe:/a:eticket:eticket:1.5.6_rc2" />
                <cpe-lang:fact-ref name="cpe:/a:eticket:eticket:1.5.6_rc3" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:eticket:eticket:1.5.5.2</vuln:product>
            <vuln:product>cpe:/a:eticket:eticket:1.5.6_rc3</vuln:product>
            <vuln:product>cpe:/a:eticket:eticket:1.5.6_rc2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0093</vuln:cve-id>
        <vuln:published-datetime>2008-01-07T20:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:11.857-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-08T10:19:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-79" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.digitrustgroup.com/advisories/web-application-security-eticket.html">http://www.digitrustgroup.com/advisories/web-application-security-eticket.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28331">28331</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39400">eticket-name-subject-xss(39400)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27130">27130</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in newticket.php in eTicket 1.5.5.2, and 1.5.6 RC2 and RC3, allow remote attackers to inject arbitrary web script or HTML via the (1) Name and (2) Subject parameters.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0094">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:modxcms:modxcms:0.9.6.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:modxcms:modxcms:0.9.6.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0094</vuln:cve-id>
        <vuln:published-datetime>2008-01-07T21:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-10-11T01:48:31.607-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>6.4</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-08T10:28:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-22" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28220">28220</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39352">modx-ajaxsearch-file-include(39352)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27097">27097</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27096">27096</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/485707/100/0/threaded">20080102 MODx CMS Source code disclosure, local file inclusion</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://modxcms.com/forums/index.php/topic,21290.0.html">http://modxcms.com/forums/index.php/topic,21290.0.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/3522">3522</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple directory traversal vulnerabilities in MODx Content Management System 0.9.6.1 allow remote attackers to (1) include and execute arbitrary local files via a .. (dot dot) in the as_language parameter to assets/snippets/AjaxSearch/AjaxSearch.php, reached through index-ajax.php; and (2) read arbitrary local files via a .. (dot dot) in the file parameter to assets/js/htcmime.php.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0095">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:asterisk:asterisk_appliance_developer_kit:1.4_revision_95945" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:asterisk_business_edition:c.1.0beta7" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:asterisknow:beta_6" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.16" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:s800i:1.0.3.3" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:asterisk:asterisknow:beta_6</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.4.16</vuln:product>
            <vuln:product>cpe:/a:asterisk:asterisk_business_edition:c.1.0beta7</vuln:product>
            <vuln:product>cpe:/a:asterisk:asterisk_appliance_developer_kit:1.4_revision_95945</vuln:product>
            <vuln:product>cpe:/a:asterisk:s800i:1.0.3.3</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0095</vuln:cve-id>
        <vuln:published-datetime>2008-01-07T21:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-09-11T01:17:32.017-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-08T10:36:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-399" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27110">27110</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28312">28312</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://downloads.digium.com/pub/security/AST-2008-001.html">http://downloads.digium.com/pub/security/AST-2008-001.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://bugs.digium.com/view.php?id=11637">http://bugs.digium.com/view.php?id=11637</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00167.html">FEDORA-2008-0199</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00166.html">FEDORA-2008-0198</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39361">asterisk-bye-also-dos(39361)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1019152">1019152</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/485727/100/0/threaded">20080102 AST-2008-001: Crash from transfer using BYE with Also header</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/0019">ADV-2008-0019</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28299">28299</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/3520">3520</vuln:reference>
        </vuln:references>
        <vuln:summary>The SIP channel driver in Asterisk Open Source 1.4.x before 1.4.17, Business Edition before C.1.0-beta8, AsteriskNOW before beta7, Appliance Developer Kit before Asterisk 1.4 revision 95946, and Appliance s800i 1.0.x before 1.0.3.4 allows remote attackers to cause a denial of service (daemon crash) via a BYE message with an Also (Also transfer) header, which triggers a NULL pointer dereference.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0096">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:georgia_softworks:ssh2_server:7.01.0003" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:georgia_softworks:ssh2_server:7.01.0003</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0096</vuln:cve-id>
        <vuln:published-datetime>2008-01-07T21:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-09-15T01:10:28.657-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-08T11:04:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-119" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27103">27103</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/485725/100/0/threaded">20080102 Multiple vulnerabilities in Georgia SoftWorks SSH2 Server 7.01.0003</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28307">28307</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://aluigi.altervista.org/adv/gswsshit-adv.txt">http://aluigi.altervista.org/adv/gswsshit-adv.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/3517">3517</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple buffer overflows in Georgia SoftWorks SSH2 Server (GSW_SSHD) 7.01.0003 and earlier allow remote attackers to execute arbitrary code via a (1) a long username, which triggers an overflow in the log function; or (2) a long password.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0097">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:georgia_softworks:ssh2_server:7.01.0003" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:georgia_softworks:ssh2_server:7.01.0003</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0097</vuln:cve-id>
        <vuln:published-datetime>2008-01-07T21:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:12.467-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-08T11:08:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-20" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/485725/100/0/threaded">20080102 Multiple vulnerabilities in Georgia SoftWorks SSH2 Server 7.01.0003</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28307">28307</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://aluigi.altervista.org/adv/gswsshit-adv.txt">http://aluigi.altervista.org/adv/gswsshit-adv.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/3517">3517</vuln:reference>
        </vuln:references>
        <vuln:summary>Format string vulnerability in the log function in Georgia SoftWorks SSH2 Server (GSW_SSHD) 7.01.0003 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the username field, as demonstrated by a certain LoginPassword message.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0098">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:real:realplayer:11_build_6.0.14.748" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:real:realplayer:11_build_6.0.14.748</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0098</vuln:cve-id>
        <vuln:published-datetime>2008-01-07T21:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:12.623-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>10.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-08T11:11:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-119" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.us-cert.gov/current/index.html#public_exploit_code_for_realplayer">http://www.us-cert.gov/current/index.html#public_exploit_code_for_realplayer</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27091">27091</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/0016">ADV-2008-0016</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28276">28276</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.immunitysec.com/pipermail/dailydave/2008-January/004811.html">[Dailydave] 20080101 0day RealPlayer exploit demo</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://gleg.net/realplayer11.html">http://gleg.net/realplayer11.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1019153">1019153</vuln:reference>
        </vuln:references>
        <vuln:summary>Buffer overflow in RealPlayer 11 build 6.0.14.748 allows remote attackers to execute arbitrary code via unspecified vectors.  NOTE: As of 20080103, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0099">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:myphp_forum:myphp_forum:3.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:myphp_forum:myphp_forum:3.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0099</vuln:cve-id>
        <vuln:published-datetime>2008-01-07T21:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-09-16T01:14:07.767-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>6.8</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-08T11:28:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-89" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27118">27118</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/4831">4831</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple SQL injection vulnerabilities in MyPHP Forum 3.0 and earlier allow remote attackers to execute arbitrary SQL commands via the searchtext parameter to search.php, and unspecified other vectors.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0100">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:white_dune:white_dune:0.29beta791" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:white_dune:white_dune:0.29beta791</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0100</vuln:cve-id>
        <vuln:published-datetime>2008-01-07T21:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-10-11T01:48:32.387-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-08T11:36:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-119" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27102">27102</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28287">28287</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39385">whitedune-sceneerrorf-bo(39385)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/485724/100/0/threaded">20080102 Buffer-overflow and format string in White_Dune 0.29beta791</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://vrml.cip.ica.uni-stuttgart.de/dune/news.html">http://vrml.cip.ica.uni-stuttgart.de/dune/news.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://aluigi.altervista.org/adv/whitedunboffs-adv.txt">http://aluigi.altervista.org/adv/whitedunboffs-adv.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/3516">3516</vuln:reference>
        </vuln:references>
        <vuln:summary>Stack-based buffer overflow in the Scene::errorf function in Scene.cpp in White_Dune 0.29 beta791 and earlier allows remote attackers to execute arbitrary code via a long string in a .WRL file.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0101">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:white_dune:white_dune:0.29beta791" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:white_dune:white_dune:0.29beta791</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0101</vuln:cve-id>
        <vuln:published-datetime>2008-01-07T21:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-10-11T01:48:32.497-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-08T11:38:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-20" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27102">27102</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28287">28287</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39388">whitedune-swdegugf-format-string(39388)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/485724/100/0/threaded">20080102 Buffer-overflow and format string in White_Dune 0.29beta791</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://vrml.cip.ica.uni-stuttgart.de/dune/news.html">http://vrml.cip.ica.uni-stuttgart.de/dune/news.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://aluigi.altervista.org/adv/whitedunboffs-adv.txt">http://aluigi.altervista.org/adv/whitedunboffs-adv.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/3516">3516</vuln:reference>
        </vuln:references>
        <vuln:summary>Format string vulnerability in the swDebugf function in DuneApp.cpp in White_Dune 0.29 beta791 and earlier allows remote attackers to execute arbitrary code via format string specifiers in a .WRL file.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0129">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:siteatschool:siteatschool:2.3.10" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:siteatschool:siteatschool:2.3.10</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0129</vuln:cve-id>
        <vuln:published-datetime>2008-01-08T06:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:17.343-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>6.8</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-08T11:49:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-89" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/4832">4832</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39417">siteatschool-slideshowfull-sql-injection(39417)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27120">27120</vuln:reference>
        </vuln:references>
        <vuln:summary>SQL injection vulnerability in starnet/addons/slideshow_full.php in Site@School 2.3.10 and earlier allows remote attackers to execute arbitrary SQL commands via the album_name parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0130">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:instantsoftwares:dating_site" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:instantsoftwares:dating_site</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0130</vuln:cve-id>
        <vuln:published-datetime>2008-01-08T06:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-11-15T00:00:00.000-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-08T11:52:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-89" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39326">dating-site-login-sql-injection(39326)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28283">28283</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://osvdb.org/39766">39766</vuln:reference>
        </vuln:references>
        <vuln:summary>SQL injection vulnerability in login_form.asp in Instant Softwares Dating Site allows remote attackers to execute arbitrary SQL commands via the Username parameter, a different vulnerability than CVE-2007-6671.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0131">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:instantsoftwares:dating_site" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:instantsoftwares:dating_site</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0131</vuln:cve-id>
        <vuln:published-datetime>2008-01-08T06:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-09-15T01:10:32.453-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-08T11:54:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-79" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27121">27121</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28283">28283</vuln:reference>
        </vuln:references>
        <vuln:summary>Cross-site scripting (XSS) vulnerability in login_form.asp in Instant Softwares Dating Site allows remote attackers to inject arbitrary web script or HTML via the msg parameter, a different product than CVE-2006-6022.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0132">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:pragma_systems:fortressssh:5.0_build_4_r_293" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:pragma_systems:fortressssh:5.0_build_4_r_293</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0132</vuln:cve-id>
        <vuln:published-datetime>2008-01-08T06:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:17.780-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-08T11:58:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-399" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39354">fortressssh-sshd-dos(39354)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://aluigi.org/poc/pragmassh.zip">http://aluigi.org/poc/pragmassh.zip</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://aluigi.altervista.org/adv/pragmassh-adv.txt">http://aluigi.altervista.org/adv/pragmassh-adv.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27141">27141</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=bugtraq&amp;m=119947184730448&amp;w=2">20080104 Some DoS in some telnet servers</vuln:reference>
        </vuln:references>
        <vuln:summary>Pragma FortressSSH 5.0 Build 4 Revision 293 and earlier handles long input to sshd.exe by creating an error-message window and waiting for the administrator to click in this window before terminating the sshd.exe process, which allows remote attackers to cause a denial of service (connection slot exhaustion) via a flood of SSH connections with long data objects, as demonstrated by (1) a long list of keys and (2) a long username.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0133">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:thomas_perez:tribisur:2.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:thomas_perez:tribisur:2.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0133</vuln:cve-id>
        <vuln:published-datetime>2008-01-08T14:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:17.937-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-08T15:04:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-89" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27149">27149</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/4840">4840</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28362">28362</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39443">tribisur-catmain-forum-sql-injection(39443)</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple SQL injection vulnerabilities in Tribisur 2.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to cat_main.php and the (2) cat parameter to forum.php in a liste action.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0134">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:snitz_forums_2000:snitz_forums:3.4.06" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:snitz_forums_2000:snitz_forums:3.4.06</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0134</vuln:cve-id>
        <vuln:published-datetime>2008-01-08T14:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-09-11T01:17:36.280-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-08T15:07:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-79" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27162">27162</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/485836/100/200/threaded">20080107 [HSC] Snitz Forums Multiple Vulnerabilities</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.packetstormsecurity.org/0801-exploits/snitz-multi.txt">http://www.packetstormsecurity.org/0801-exploits/snitz-multi.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28284">28284</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://hackerscenter.com/archive/view.asp?id=28145">http://hackerscenter.com/archive/view.asp?id=28145</vuln:reference>
        </vuln:references>
        <vuln:summary>Cross-site scripting (XSS) vulnerability in Forums/setup.asp in Snitz Forums 2000 3.4.06 and earlier allows remote attackers to inject arbitrary web script or HTML via the MAIL parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0135">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:snitz_forums_2000:snitz_forums:3.4.06" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:snitz_forums_2000:snitz_forums:3.4.06</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0135</vuln:cve-id>
        <vuln:published-datetime>2008-01-08T14:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-09-11T01:17:36.420-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-08T15:16:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-264" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/485894/100/200/threaded">20080107 RE: [HSC] Snitz Forums Multiple Vulnerabilities</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/485836/100/200/threaded">20080107 [HSC] Snitz Forums Multiple Vulnerabilities</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.packetstormsecurity.org/0801-exploits/snitz-multi.txt">http://www.packetstormsecurity.org/0801-exploits/snitz-multi.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://hackerscenter.com/archive/view.asp?id=28145">http://hackerscenter.com/archive/view.asp?id=28145</vuln:reference>
        </vuln:references>
        <vuln:summary>Snitz Forums 2000 3.4.06 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for forum/snitz_forums_2000.mdb.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0136">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:snitz_forums_2000:snitz_forums:3.4.05" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:snitz_forums_2000:snitz_forums:3.4.05</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0136</vuln:cve-id>
        <vuln:published-datetime>2008-01-08T14:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-09-11T01:17:36.563-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-08T15:18:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-200" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/485894/100/200/threaded">20080107 RE: [HSC] Snitz Forums Multiple Vulnerabilities</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/485836/100/200/threaded">20080107 [HSC] Snitz Forums Multiple Vulnerabilities</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.packetstormsecurity.org/0801-exploits/snitz-multi.txt">http://www.packetstormsecurity.org/0801-exploits/snitz-multi.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://hackerscenter.com/archive/view.asp?id=28145">http://hackerscenter.com/archive/view.asp?id=28145</vuln:reference>
        </vuln:references>
        <vuln:summary>Snitz Forums 2000 3.4.05 allows remote attackers to obtain sensitive information via a direct request to forum/whereami.asp, which reveals the database path.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0137">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:snetworks:php_classifieds:5.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:snetworks:php_classifieds:5.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0137</vuln:cve-id>
        <vuln:published-datetime>2008-01-08T14:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:18.513-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-09T10:23:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-89" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/4838">4838</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/0053">ADV-2008-0053</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39468">snetworks-configinc-file-include(39468)</vuln:reference>
        </vuln:references>
        <vuln:summary>PHP remote file inclusion vulnerability in config.inc.php in SNETWORKS PHP CLASSIFIEDS 5.0 allows remote attackers to execute arbitrary PHP code via a URL in the path_escape parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0138">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:xoops:xoopsgallery_module:1.3.3_9" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:xoops:xoopsgallery_module:1.3.3_9</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0138</vuln:cve-id>
        <vuln:published-datetime>2008-01-08T14:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:18.670-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>6.8</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-09T10:30:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-89" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39461">xoops-modgallery-zendhashkey-file-include(39461)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27155">27155</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/4847">4847</vuln:reference>
        </vuln:references>
        <vuln:summary>PHP remote file inclusion vulnerability in xoopsgallery/init_basic.php in the mod_gallery module for XOOPS, when register_globals is disabled, allows remote attackers to execute arbitrary PHP code via a URL in the GALLERY_BASEDIR parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0139">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:loudblog:loudblog:0.8.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:loudblog:loudblog:0.8.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0139</vuln:cve-id>
        <vuln:published-datetime>2008-01-08T14:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:18.810-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>6.8</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-09T10:35:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-89" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27157">27157</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28336">28336</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://milw0rm.com/exploits/4849">4849</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39445">loudblog-template-code-execution(39445)</vuln:reference>
        </vuln:references>
        <vuln:summary>Eval injection vulnerability in loudblog/inc/parse_old.php in Loudblog 0.8.0 and earlier allows remote attackers to execute arbitrary PHP code via the template parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0140">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:uebimiau:webmail:2.7.10" />
                <cpe-lang:fact-ref name="cpe:/a:uebimiau:webmail:2.7.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:uebimiau:webmail:2.7.10</vuln:product>
            <vuln:product>cpe:/a:uebimiau:webmail:2.7.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0140</vuln:cve-id>
        <vuln:published-datetime>2008-01-08T14:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-10-22T01:44:05.437-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>6.4</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-09T10:38:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-22" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39460">uebimiau-webmail-error-directory-traversal(39460)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27154">27154</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/4846">4846</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VIM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.attrition.org/pipermail/vim/2008-January/001867.html">20080107 Uebimiau Web-Mail 2.7.10/2.7.2 Remote File Disclosure Vulnerability</vuln:reference>
        </vuln:references>
        <vuln:summary>Directory traversal vulnerability in error.php in Uebimiau Webmail 2.7.10 and 2.7.2 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the selected_theme parameter, a different vector than CVE-2007-3172.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0141">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:webportal:webportal_cms:0.6_beta" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:webportal:webportal_cms:0.6_beta</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0141</vuln:cve-id>
        <vuln:published-datetime>2008-01-08T14:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:19.123-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-09T10:44:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-255" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27145">27145</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/4835">4835</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39486">webportal-action-weak-security(39486)</vuln:reference>
        </vuln:references>
        <vuln:summary>actions.php in WebPortal CMS 0.6-beta generates predictable passwords containing only the time of day, which makes it easier for remote attackers to obtain access to any account via a lostpass action.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0142">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:webportal:webportal_cms:0.6_beta" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:webportal:webportal_cms:0.6_beta</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0142</vuln:cve-id>
        <vuln:published-datetime>2008-01-08T14:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:19.263-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>6.8</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-09T10:50:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-89" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/4835">4835</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple SQL injection vulnerabilities in WebPortal CMS 0.6-beta allow remote attackers to execute arbitrary SQL commands via the user_name parameter to actions.php, and unspecified other vectors.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0143">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:spacial_audio_solutions:sam_broadcaster" />
                <cpe-lang:fact-ref name="cpe:/a:spacial_audio_solutions:samphpweb" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:spacial_audio_solutions:sam_broadcaster</vuln:product>
            <vuln:product>cpe:/a:spacial_audio_solutions:samphpweb</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0143</vuln:cve-id>
        <vuln:published-datetime>2008-01-08T14:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:19.420-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-09T10:56:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-94" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39397">samPHPweb-db-file-include(39397)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.spacialaudio.com/news/index.html">http://www.spacialaudio.com/news/index.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27137">27137</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/4834">4834</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28355">28355</vuln:reference>
        </vuln:references>
        <vuln:summary>PHP remote file inclusion vulnerability in common/db.php in samPHPweb, possibly 4.2.2 and others, as provided with SAM Broadcaster, allows remote attackers to execute arbitrary PHP code via a URL in the commonpath parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0144">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:phprisk:netrisk:1.9.7" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:phprisk:netrisk:1.9.7</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0144</vuln:cve-id>
        <vuln:published-datetime>2008-01-08T14:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-09-15T01:10:34.750-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-09T11:05:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-89" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39419">netrisk-index-file-include(39419)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27136">27136</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/4833">4833</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28328">28328</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=bugtraq&amp;m=119955114428283&amp;w=2">20080105 NetRisk 1.9.7 Remote File Inclusion Vulnerability</vuln:reference>
        </vuln:references>
        <vuln:summary>PHP remote file inclusion vulnerability in index.php in NetRisk 1.9.7 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.  NOTE: this can also be leveraged for local file inclusion using directory traversal sequences.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0145">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.7" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:php:php:4.4.7</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0145</vuln:cve-id>
        <vuln:published-datetime>2008-01-08T14:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-09-16T01:14:13.390-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-09T11:12:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-264" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39401">php-glob-openbasedir-security-bypass(39401)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vupen.com/english/advisories/2008/0059">ADV-2008-0059</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.php.net/releases/4_4_8.php">http://www.php.net/releases/4_4_8.php</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.php.net/ChangeLog-4.php">http://www.php.net/ChangeLog-4.php</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28318">28318</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://bugs.php.net/bug.php?id=41655">http://bugs.php.net/bug.php?id=41655</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SLACKWARE</vuln:source>
            <vuln:reference xml:lang="en" href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2008&amp;m=slackware-security.335136">SSA:2008-045-03</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28936">28936</vuln:reference>
        </vuln:references>
        <vuln:summary>Unspecified vulnerability in glob in PHP before 4.4.8, when open_basedir is enabled, has unknown impact and attack vectors.  NOTE: this issue reportedly exists because of a regression related to CVE-2007-4663.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0146">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:hughes_technologies:w3-msql" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:hughes_technologies:w3-msql</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0146</vuln:cve-id>
        <vuln:published-datetime>2008-01-08T14:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-09-15T01:10:34.953-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-09T11:15:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-79" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27116">27116</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/485736/100/0/threaded">20080103 xss in w3-msql error page</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28294">28294</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://osvdb.org/51235">51235</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/3521">3521</vuln:reference>
        </vuln:references>
        <vuln:summary>Cross-site scripting (XSS) vulnerability in the error page in W3-mSQL allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the top-level URI.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0003">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="AND">
                <cpe-lang:logical-test negate="false" operator="OR">
                    <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:4.0::as" />
                    <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:4.0::es" />
                    <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:4.0::ws" />
                    <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:4.5.z::as" />
                    <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:4.5.z::es" />
                    <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux_desktop:4.0" />
                    <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux_desktop:5.0" />
                </cpe-lang:logical-test>
                <cpe-lang:logical-test negate="false" operator="OR">
                    <cpe-lang:fact-ref name="cpe:/a:openpegasus:management_server:2.6.1" />
                </cpe-lang:logical-test>
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:openpegasus:management_server:2.6.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0003</vuln:cve-id>
        <vuln:published-datetime>2008-01-08T15:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-02-21T00:00:00.000-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>10.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-09T13:14:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:cwe id="CWE-119" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27188">27188</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2008-0002.html">RHSA-2008:0002</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/0063">ADV-2008-0063</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00480.html">FEDORA-2008-0572</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00424.html">FEDORA-2008-0506</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://bugzilla.redhat.com/show_bug.cgi?id=426578">https://bugzilla.redhat.com/show_bug.cgi?id=426578</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39527">openpegasus-pambasic-bo(39527)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&amp;ID=4129">http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&amp;ID=4129</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27172">27172</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/490917/100/0/threaded">20080416 VMSA-2008-0007 Moderate Updated Service Console packages pcre, net-snmp, and OpenPegasus</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/1391/references">ADV-2008-1391</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/1234/references">ADV-2008-1234</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/0638">ADV-2008-0638</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VIM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.attrition.org/pipermail/vim/2008-January/001879.html">20080115 vuldb confusion between OpenPegasus issues</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1019159">1019159</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/29986">29986</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/29785">29785</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/29056">29056</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28462">28462</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28338">28338</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://osvdb.org/40082">40082</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.vmware.com/pipermail/security-announce/2008/000014.html">[Security-announce] 20080415 VMSA-2008-0007 Moderate Updated Service Console packages pcre, net-snmp, and OpenPegasus</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01438409">SSRT080000</vuln:reference>
        </vuln:references>
        <vuln:summary>Stack-based buffer overflow in the PAMBasicAuthenticator::PAMCallback function in OpenPegasus CIM management server (tog-pegasus), when compiled to use PAM and without PEGASUS_USE_PAM_STANDALONE_PROC defined, might allow remote attackers to execute arbitrary code via unknown vectors, a different vulnerability than CVE-2007-5360.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0147">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:smallnuke:smallnuke:2.0.4" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:smallnuke:smallnuke:2.0.4</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0147</vuln:cve-id>
        <vuln:published-datetime>2008-01-08T19:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:20.013-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>6.8</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-09T13:47:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-89" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27180">27180</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/4863">4863</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28301">28301</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39525">smallnuke-index-sql-injection(39525)</vuln:reference>
        </vuln:references>
        <vuln:summary>SQL injection vulnerability in index.php in SmallNuke 2.0.4 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via (1) the user_email parameter and possibly (2) username parameter in a Members action.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0148">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:tutos:tutos:1.3" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:tutos:tutos:1.3</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0148</vuln:cve-id>
        <vuln:published-datetime>2008-01-08T19:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:20.153-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>10.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-09T13:50:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-264" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28291">28291</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://milw0rm.com/exploits/4861">4861</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39531">tutos-cmd-command-execution(39531)</vuln:reference>
        </vuln:references>
        <vuln:summary>TUTOS 1.3 does not restrict access to php/admin/cmd.php, which allows remote attackers to execute arbitrary shell commands via the cmd parameter in a direct request.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0149">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:tutos:tutos:1.3" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:tutos:tutos:1.3</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0149</vuln:cve-id>
        <vuln:published-datetime>2008-01-08T19:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:20.310-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-09T13:53:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28291">28291</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://milw0rm.com/exploits/4861">4861</vuln:reference>
        </vuln:references>
        <vuln:summary>TUTOS 1.3 allows remote attackers to read system information via a direct request to php/admin/phpinfo.php, which calls the phpinfo function.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0150">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:aruba_networks:aruba_mobility_controllers:2.3.6.15" />
                <cpe-lang:fact-ref name="cpe:/a:aruba_networks:aruba_mobility_controllers:2.5.2.11" />
                <cpe-lang:fact-ref name="cpe:/a:aruba_networks:aruba_mobility_controllers:2.5.4.25" />
                <cpe-lang:fact-ref name="cpe:/a:aruba_networks:aruba_mobility_controllers:2.5.5.7" />
                <cpe-lang:fact-ref name="cpe:/a:aruba_networks:aruba_mobility_controllers:3.1.1.3" />
                <cpe-lang:fact-ref name="cpe:/a:aruba_networks:aruba_mobility_controllers:2.4.8.11-fips" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:aruba_networks:aruba_mobility_controllers:2.4.8.11-fips</vuln:product>
            <vuln:product>cpe:/a:aruba_networks:aruba_mobility_controllers:2.5.2.11</vuln:product>
            <vuln:product>cpe:/a:aruba_networks:aruba_mobility_controllers:2.3.6.15</vuln:product>
            <vuln:product>cpe:/a:aruba_networks:aruba_mobility_controllers:3.1.1.3</vuln:product>
            <vuln:product>cpe:/a:aruba_networks:aruba_mobility_controllers:2.5.4.25</vuln:product>
            <vuln:product>cpe:/a:aruba_networks:aruba_mobility_controllers:2.5.5.7</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0150</vuln:cve-id>
        <vuln:published-datetime>2008-01-08T19:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:20.450-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>6.8</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-09T13:59:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-287" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27144">27144</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/485831/100/0/threaded">20080104 Aruba Mobility Controller User Authentication Vulnerability - Aruba Advisory ID: AID-122207</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.arubanetworks.com/support/alerts/aid-122207.asc">http://www.arubanetworks.com/support/alerts/aid-122207.asc</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28357">28357</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/3529">3529</vuln:reference>
        </vuln:references>
        <vuln:summary>Unspecified vulnerability in the LDAP authentication feature in Aruba Mobility Controller 2.3.6.15, 2.5.2.11, 2.5.4.25, 2.5.5.7, 3.1.1.3, and 2.4.8.11-FIPS or earlier allows remote attackers to bypass authentication mechanisms and obtain management or VPN interface access.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0151">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:foxitsoftware:wac_server:2.0" />
                <cpe-lang:fact-ref name="cpe:/a:foxitsoftware:wac_server:2.1.0.910" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:foxitsoftware:wac_server:2.0</vuln:product>
            <vuln:product>cpe:/a:foxitsoftware:wac_server:2.1.0.910</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0151</vuln:cve-id>
        <vuln:published-datetime>2008-01-08T19:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-08-25T00:00:00.000-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>10.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-09T14:12:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-119" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39427">wacserver-option-dos(39427)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27142">27142</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/488366/100/200/threaded">20080219 Two heap overflow in Foxit WAC Server 2.0 Build 3503</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/485812/100/0/threaded">20080104 Some DoS in some telnet servers</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/3525">3525</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28272">28272</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://aluigi.altervista.org/adv/wachof-adv.txt">http://aluigi.altervista.org/adv/wachof-adv.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://aluigi.altervista.org/adv/waccaz-adv.txt">http://aluigi.altervista.org/adv/waccaz-adv.txt</vuln:reference>
        </vuln:references>
        <vuln:summary>Heap-based buffer overflow in Foxit WAC Server 2.1.0.910, 2.0 Build 3503, and earlier allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a Telnet request with long options.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0152">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:seattle_lab_software:slnet_rf_telnet_server:4.1.1.3758" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:seattle_lab_software:slnet_rf_telnet_server:4.1.1.3758</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0152</vuln:cve-id>
        <vuln:published-datetime>2008-01-08T19:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:20.763-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-09T14:16:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-119" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27134">27134</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28316">28316</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=bugtraq&amp;m=119947184730448&amp;w=2">20080104 Some DoS in some telnet servers</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://aluigi.altervista.org/adv/slnetmsg-adv.txt">http://aluigi.altervista.org/adv/slnetmsg-adv.txt</vuln:reference>
        </vuln:references>
        <vuln:summary>SLnet.exe in SeattleLab SLNet RF Telnet Server 4.1.1.3758 and earlier allows user-assisted remote attackers to cause a denial of service (crash) via unpsecified telnet options, which triggers a NULL pointer dereference.  NOTE: the crash is not user-assisted when the server is running in debug mode.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0153">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:pragma_systems:pragma_telnetserver:7.0.4.589" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:pragma_systems:pragma_telnetserver:7.0.4.589</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0153</vuln:cve-id>
        <vuln:published-datetime>2008-01-08T19:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-10-11T01:48:37.560-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-09T14:21:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-399" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39353">pragmatelnetserver-telnetd-dos(39353)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27143">27143</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=bugtraq&amp;m=119947184730448&amp;w=2">20080104 Some DoS in some telnet servers</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://aluigi.altervista.org/adv/pragmatel-adv.txt">http://aluigi.altervista.org/adv/pragmatel-adv.txt</vuln:reference>
        </vuln:references>
        <vuln:summary>telnetd.exe in Pragma TelnetServer 7.0.4.589 allows remote attackers to cause a denial of service (process crash and resource exhaustion) via a crafted TELOPT PRAGMA LOGON telnet option, which triggers a NULL pointer dereference.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0154">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:evilboard:evilboard:0.1a" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:evilboard:evilboard:0.1a</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0154</vuln:cve-id>
        <vuln:published-datetime>2008-01-08T19:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-09-15T01:10:35.703-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-09T14:24:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-89" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39529">evilboard-index-sql-injection(39529)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27190">27190</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/4865">4865</vuln:reference>
        </vuln:references>
        <vuln:summary>SQL injection vulnerability in index.php in EvilBoard 0.1a (Alpha) allows remote attackers to execute arbitrary SQL commands the c parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0155">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:evilboard:evilboard:0.1a" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:evilboard:evilboard:0.1a</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0155</vuln:cve-id>
        <vuln:published-datetime>2008-01-08T19:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-09-15T01:10:35.920-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-09T14:25:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-79" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27190">27190</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/4865">4865</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39526">evilboard-index-xss(39526)</vuln:reference>
        </vuln:references>
        <vuln:summary>Cross-site scripting (XSS) vulnerability in index.php in EvilBoard 0.1a (Alpha) allows remote attackers to inject arbitrary web script or HTML via the c parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0156">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:million_dollar_script:million_dollar_script:2.0.14" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:million_dollar_script:million_dollar_script:2.0.14</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0156</vuln:cve-id>
        <vuln:published-datetime>2008-01-08T19:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:21.343-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-09T14:28:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-22" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39492">milliondollarscript-index-dir-traversal(39492)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27174">27174</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/485882/100/0/threaded">20080107 Million Dollar Script 2.0.14 Remote File Disclosure Vulnerability.</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/3524">3524</vuln:reference>
        </vuln:references>
        <vuln:summary>Absolute path traversal vulnerability in index.php in Million Dollar Script 2.0.14 allows remote attackers to read arbitrary files via encoded "/" (%2F) sequences in the link parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0157">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:flexbb:flexbb:1.0_10005_beta_release_1" />
                <cpe-lang:fact-ref name="cpe:/a:flexbb:flexbb:0.6.3" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:flexbb:flexbb:0.6.3</vuln:product>
            <vuln:product>cpe:/a:flexbb:flexbb:1.0_10005_beta_release_1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0157</vuln:cve-id>
        <vuln:published-datetime>2008-01-08T19:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:21.483-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-09T14:31:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-89" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39475">flexbb-flexbbtempid-sql-injection(39475)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27164">27164</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/4858">4858</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28373">28373</vuln:reference>
        </vuln:references>
        <vuln:summary>SQL injection vulnerability in FlexBB 0.6.3 and earlier allows remote attackers to execute arbitrary SQL commands via the flexbb_temp_id parameter in a cookie.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0158">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:shop-script:shop-script:2.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:shop-script:shop-script:2.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0158</vuln:cve-id>
        <vuln:published-datetime>2008-01-08T19:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:21.640-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-09T14:35:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-22" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39449">shopscript-index-directory-traversal(39449)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27165">27165</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://packetstormsecurity.org/0801-exploits/shopscript-disclose.txt">http://packetstormsecurity.org/0801-exploits/shopscript-disclose.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/4855">4855</vuln:reference>
        </vuln:references>
        <vuln:summary>Directory traversal vulnerability in index.php in Shop-Script 2.0 and possibly other versions allows remote attackers to read arbitrary files via a .. (dot dot) in the aux_page parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0159">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:eggblog:eggblog:3.1.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:eggblog:eggblog:3.1.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0159</vuln:cve-id>
        <vuln:published-datetime>2008-01-08T19:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:21.780-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>6.8</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-09T14:38:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-89" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39473">eggblog-eggblogmail-sql-injection(39473)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27168">27168</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/4860">4860</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28371">28371</vuln:reference>
        </vuln:references>
        <vuln:summary>SQL injection vulnerability in index.php in eggBlog 3.1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the eggblogpassword parameter in a cookie.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0184">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:prenotazioni_on_line:syshotel_on_line_system" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:prenotazioni_on_line:syshotel_on_line_system</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0184</vuln:cve-id>
        <vuln:published-datetime>2008-01-09T17:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:25.137-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>6.4</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-10T10:50:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-22" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27184">27184</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/485940/100/0/threaded">20080108 sysHotel On Line Remote File Disclosure Vulnerability.</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/3528">3528</vuln:reference>
        </vuln:references>
        <vuln:summary>Absolute path traversal vulnerability in index.php in Sys-Hotel on Line System allows remote attackers to read arbitrary files via an encoded "/" ("%2F") in the file parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0185">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:netrisk:netrisk:1.9.7" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:netrisk:netrisk:1.9.7</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0185</vuln:cve-id>
        <vuln:published-datetime>2008-01-09T17:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-09-11T01:17:43.547-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-10T10:53:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-89" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27161">27161</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/4852">4852</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://sourceforge.net/project/shownotes.php?release_id=551208&amp;group_id=129681">http://sourceforge.net/project/shownotes.php?release_id=551208&amp;group_id=129681</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28328">28328</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/485834/100/0/threaded">20080106 netrisk 1.9.7 Multiple Remote Vulnerabilities (sql injection/xss)</vuln:reference>
        </vuln:references>
        <vuln:summary>SQL injection vulnerability in index.php in NetRisk 1.9.7 and possibly earlier versions allows remote attackers to execute arbitrary SQL commands via the pid parameter in a profile page (possibly profile.php).</vuln:summary>
    </entry>
    <entry id="CVE-2008-0186">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:phprisk:netrisk:1.9.7" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:phprisk:netrisk:1.9.7</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0186</vuln:cve-id>
        <vuln:published-datetime>2008-01-09T17:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-09-11T01:17:43.670-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-10T10:53:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-79" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27161">27161</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/4852">4852</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/485834/100/0/threaded">20080106 netrisk 1.9.7 Multiple Remote Vulnerabilities (sql injection/xss)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28369">28369</vuln:reference>
        </vuln:references>
        <vuln:summary>Cross-site scripting (XSS) vulnerability in index.php in NetRisk 1.9.7 and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the page parameter, possibly related to CVE-2008-0144.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0187">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:spacial_audio_solutions:samphpweb:4.2.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:spacial_audio_solutions:samphpweb:4.2.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0187</vuln:cve-id>
        <vuln:published-datetime>2008-01-09T17:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:25.577-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-10T10:55:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-89" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39463">sambroadcaster-songinfo-sql-injection(39463)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27147">27147</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/4836">4836</vuln:reference>
        </vuln:references>
        <vuln:summary>SQL injection vulnerability in songinfo.php in SAM Broadcaster samPHPweb, possibly 4.2.2 and earlier, allows remote attackers to execute arbitrary SQL commands via the songid parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0190">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:awesometemplateengine:awesometemplateengine:1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:awesometemplateengine:awesometemplateengine:1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0190</vuln:cve-id>
        <vuln:published-datetime>2008-01-09T19:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:25.903-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-10T11:25:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-79" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39396">awesometemplateengine-multiple-xss(39396)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27125">27125</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/485786/100/0/threaded">20080103 securityvulns.com russian vulnerabilities digest</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://websecurity.com.ua/1694/">http://websecurity.com.ua/1694/</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityvulns.ru/Sdocument784.html">http://securityvulns.ru/Sdocument784.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FULLDISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html">20080103 securityvulns.com russian vulnerabilities digest</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/3539">3539</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in templates/example_template.php in AwesomeTemplateEngine allow remote attackers to inject arbitrary web script or HTML via the (1) data[title], (2) data[message], (3) data[table][1][item], (4) data[table][1][url], or (5) data[poweredby] parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0191">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.2" />
                <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.3" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:wordpress:wordpress:2.2</vuln:product>
            <vuln:product>cpe:/a:wordpress:wordpress:2.3</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0191</vuln:cve-id>
        <vuln:published-datetime>2008-01-09T19:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:26.060-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-10T11:27:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-200" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39423">wordpress-p-path-disclosure(39423)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/485786/100/0/threaded">20080103 securityvulns.com russian vulnerabilities digest</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://websecurity.com.ua/1634/">http://websecurity.com.ua/1634/</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityvulns.ru/Sdocument663.html">http://securityvulns.ru/Sdocument663.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FULLDISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html">20080103 securityvulns.com russian vulnerabilities digest</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/3539">3539</vuln:reference>
        </vuln:references>
        <vuln:summary>WordPress 2.2.x and 2.3.x allows remote attackers to obtain sensitive information via an invalid p parameter in an rss2 action to the default URI, which reveals the full path and the SQL database structure.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0192">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.0.9" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:wordpress:wordpress:2.0.9</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0192</vuln:cve-id>
        <vuln:published-datetime>2008-01-09T19:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:26.200-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-10T11:32:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-79" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39426">wordpress-popuptitle-xss(39426)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27123">27123</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://websecurity.com.ua/1658/">http://websecurity.com.ua/1658/</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityvulns.ru/Sdocument714.html">http://securityvulns.ru/Sdocument714.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FULLDISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html">20080103 securityvulns.com russian vulnerabilities digest</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/3539">3539</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in WordPress 2.0.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the popuptitle parameter to (1) wp-admin/post.php or (2) wp-admin/page-new.php.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0193">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.1" />
                <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.1.1" />
                <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.1.2" />
                <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.1.3" />
                <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.1.3_rc1" />
                <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.1.3_rc2" />
                <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.2" />
                <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.2.0" />
                <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.2.1" />
                <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.2.2" />
                <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.2.3" />
                <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.2_revision5002" />
                <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.2_revision5003" />
                <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.3" />
                <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.0.11" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:wordpress:wordpress:2.1.3_rc1</vuln:product>
            <vuln:product>cpe:/a:wordpress:wordpress:2.2.3</vuln:product>
            <vuln:product>cpe:/a:wordpress:wordpress:2.2.2</vuln:product>
            <vuln:product>cpe:/a:wordpress:wordpress:2.2.1</vuln:product>
            <vuln:product>cpe:/a:wordpress:wordpress:2.2.0</vuln:product>
            <vuln:product>cpe:/a:wordpress:wordpress:2.2_revision5003</vuln:product>
            <vuln:product>cpe:/a:wordpress:wordpress:2.1.3</vuln:product>
            <vuln:product>cpe:/a:wordpress:wordpress:2.1.2</vuln:product>
            <vuln:product>cpe:/a:wordpress:wordpress:2.1.1</vuln:product>
            <vuln:product>cpe:/a:wordpress:wordpress:2.1.3_rc2</vuln:product>
            <vuln:product>cpe:/a:wordpress:wordpress:2.2_revision5002</vuln:product>
            <vuln:product>cpe:/a:wordpress:wordpress:2.1</vuln:product>
            <vuln:product>cpe:/a:wordpress:wordpress:2.2</vuln:product>
            <vuln:product>cpe:/a:wordpress:wordpress:2.3</vuln:product>
            <vuln:product>cpe:/a:wordpress:wordpress:2.0.11</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0193</vuln:cve-id>
        <vuln:published-datetime>2008-01-09T19:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:26.357-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-10T11:35:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-79" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27123">27123</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/485786/100/0/threaded">20080103 securityvulns.com russian vulnerabilities digest</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://websecurity.com.ua/1676/">http://websecurity.com.ua/1676/</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityvulns.ru/Sdocument755.html">http://securityvulns.ru/Sdocument755.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FULLDISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html">20080103 securityvulns.com russian vulnerabilities digest</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2008/dsa-1502">DSA-1502</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/3539">3539</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/29014">29014</vuln:reference>
        </vuln:references>
        <vuln:summary>Cross-site scripting (XSS) vulnerability in wp-db-backup.php in WordPress 2.0.11 and earlier, and possibly 2.1.x through 2.3.x, allows remote attackers to inject arbitrary web script or HTML via the backup parameter in a wp-db-backup.php action to wp-admin/edit.php.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0194">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.0.3" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:wordpress:wordpress:2.0.3</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0194</vuln:cve-id>
        <vuln:published-datetime>2008-01-09T19:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:26.530-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-10T11:39:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:cwe id="CWE-22" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/485786/100/0/threaded">20080103 securityvulns.com russian vulnerabilities digest</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://websecurity.com.ua/1676/">http://websecurity.com.ua/1676/</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityvulns.ru/Sdocument755.html">http://securityvulns.ru/Sdocument755.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FULLDISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html">20080103 securityvulns.com russian vulnerabilities digest</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2008/dsa-1502">DSA-1502</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/3539">3539</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/29014">29014</vuln:reference>
        </vuln:references>
        <vuln:summary>Directory traversal vulnerability in wp-db-backup.php in WordPress 2.0.3 and earlier allows remote attackers to read arbitrary files, delete arbitrary files, and cause a denial of service via a .. (dot dot) in the backup parameter in a wp-db-backup.php action to wp-admin/edit.php.  NOTE: this might be the same as CVE-2006-5705.1.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0195">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.0.11" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:wordpress:wordpress:2.0.11</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0195</vuln:cve-id>
        <vuln:published-datetime>2008-01-09T19:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:26.687-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-10T11:43:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-200" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/485786/100/0/threaded">20080103 securityvulns.com russian vulnerabilities digest</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://websecurity.com.ua/1687/">http://websecurity.com.ua/1687/</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://websecurity.com.ua/1686/">http://websecurity.com.ua/1686/</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://websecurity.com.ua/1683/">http://websecurity.com.ua/1683/</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://websecurity.com.ua/1679/">http://websecurity.com.ua/1679/</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityvulns.ru/Sdocument773.html">http://securityvulns.ru/Sdocument773.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityvulns.ru/Sdocument772.html">http://securityvulns.ru/Sdocument772.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityvulns.ru/Sdocument768.html">http://securityvulns.ru/Sdocument768.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityvulns.ru/Sdocument762.html">http://securityvulns.ru/Sdocument762.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FULLDISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html">20080103 securityvulns.com russian vulnerabilities digest</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/3539">3539</vuln:reference>
        </vuln:references>
        <vuln:summary>WordPress 2.0.11 and earlier allows remote attackers to obtain sensitive information via an empty value of the page parameter to certain PHP scripts under wp-admin/, which reveals the path in various error messages.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0196">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.0.11" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:wordpress:wordpress:2.0.11</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0196</vuln:cve-id>
        <vuln:published-datetime>2008-01-09T19:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:26.827-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-10T11:45:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-22" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/485786/100/0/threaded">20080103 securityvulns.com russian vulnerabilities digest</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://websecurity.com.ua/1687/">http://websecurity.com.ua/1687/</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://websecurity.com.ua/1686/">http://websecurity.com.ua/1686/</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://websecurity.com.ua/1683/">http://websecurity.com.ua/1683/</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://websecurity.com.ua/1679/">http://websecurity.com.ua/1679/</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityvulns.ru/Sdocument773.html">http://securityvulns.ru/Sdocument773.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityvulns.ru/Sdocument772.html">http://securityvulns.ru/Sdocument772.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityvulns.ru/Sdocument768.html">http://securityvulns.ru/Sdocument768.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityvulns.ru/Sdocument762.html">http://securityvulns.ru/Sdocument762.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FULLDISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html">20080103 securityvulns.com russian vulnerabilities digest</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/3539">3539</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple directory traversal vulnerabilities in WordPress 2.0.11 and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in (1) the page parameter to certain PHP scripts under wp-admin/ or (2) the import parameter to wp-admin/admin.php, as demonstrated by discovering the full path via a request for the \..\..\wp-config pathname; and allow remote attackers to modify arbitrary files via a .. (dot dot) in the file parameter to wp-admin/templates.php.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0197">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:wordpress:wp-contactform:1.5_alpha" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:wordpress:wp-contactform:1.5_alpha</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0197</vuln:cve-id>
        <vuln:published-datetime>2008-01-09T19:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:26.967-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-10T11:45:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-79" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/485786/100/0/threaded">20080103 securityvulns.com russian vulnerabilities digest</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://websecurity.com.ua/1641/">http://websecurity.com.ua/1641/</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://websecurity.com.ua/1600/">http://websecurity.com.ua/1600/</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityvulns.ru/Sdocument667.html">http://securityvulns.ru/Sdocument667.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityvulns.ru/Sdocument546.html">http://securityvulns.ru/Sdocument546.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FULLDISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html">20080103 securityvulns.com russian vulnerabilities digest</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/3539">3539</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in wp-contact-form/options-contactform.php in the WP-ContactForm 1.5 alpha and earlier plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) wpcf_email, (2) wpcf_subject, (3) wpcf_question, (4) wpcf_answer, (5) wpcf_success_msg, (6) wpcf_error_msg, or (7) wpcf_msg parameter to wp-admin/admin.php, or (8) the SRC attribute of an IFRAME element.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0198">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:wordpress:wordpress</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0198</vuln:cve-id>
        <vuln:published-datetime>2008-01-09T19:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:27.123-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-10T11:48:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-352" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/485786/100/0/threaded">20080103 securityvulns.com russian vulnerabilities digest</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://websecurity.com.ua/1641/">http://websecurity.com.ua/1641/</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://websecurity.com.ua/1600/">http://websecurity.com.ua/1600/</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityvulns.ru/Sdocument667.html">http://securityvulns.ru/Sdocument667.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityvulns.ru/Sdocument546.html">http://securityvulns.ru/Sdocument546.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FULLDISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html">20080103 securityvulns.com russian vulnerabilities digest</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/3539">3539</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple cross-site request forgery (CSRF) vulnerabilities in wp-contact-form/options-contactform.php in the WP-ContactForm 1.5 alpha and earlier plugin for WordPress allow remote attackers to perform actions as administrators via the (1) wpcf_question, (2) wpcf_success_msg, or (3) wpcf_error_msg parameter to wp-admin/admin.php.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0199">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:pro_search:pro_search:0.16" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:pro_search:pro_search:0.16</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0199</vuln:cve-id>
        <vuln:published-datetime>2008-01-09T19:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:27.263-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-10T11:57:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-20" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/485786/100/0/threaded">20080103 securityvulns.com russian vulnerabilities digest</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://websecurity.com.ua/1259/">http://websecurity.com.ua/1259/</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://sourceforge.net/project/shownotes.php?release_id=563784&amp;group_id=149797">http://sourceforge.net/project/shownotes.php?release_id=563784&amp;group_id=149797</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityvulns.ru/Sdocument731.html">http://securityvulns.ru/Sdocument731.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FULLDISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html">20080103 securityvulns.com russian vulnerabilities digest</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/3539">3539</vuln:reference>
        </vuln:references>
        <vuln:summary>PRO-Search 0.17 and earlier allows remote attackers to cause a denial of service via certain values of the show_page and time parameters to the default URI.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0200">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:medialand:rotabanner_local:3" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:medialand:rotabanner_local:3</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0200</vuln:cve-id>
        <vuln:published-datetime>2008-01-09T19:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-09-11T01:17:44.813-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-10T12:54:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-79" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27138">27138</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/485786/100/0/threaded">20080103 securityvulns.com russian vulnerabilities digest</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://websecurity.com.ua/1442/">http://websecurity.com.ua/1442/</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityvulns.ru/Sdocument625.html">http://securityvulns.ru/Sdocument625.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FULLDISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html">20080103 securityvulns.com russian vulnerabilities digest</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/3539">3539</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in account/index.html in RotaBanner Local 3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) user or (2) drop parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0201">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:expressionengine:expressionengine:1.2.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:expressionengine:expressionengine:1.2.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0201</vuln:cve-id>
        <vuln:published-datetime>2008-01-09T19:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-10-22T01:44:13.437-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-10T12:56:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-79" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39442">expressionengine-index-xss(39442)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27128">27128</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/485786/100/0/threaded">20080103 securityvulns.com russian vulnerabilities digest</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://websecurity.com.ua/1454/">http://websecurity.com.ua/1454/</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityvulns.ru/Sdocument472.html">http://securityvulns.ru/Sdocument472.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FULLDISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html">20080103 securityvulns.com russian vulnerabilities digest</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/3539">3539</vuln:reference>
        </vuln:references>
        <vuln:summary>Cross-site scripting (XSS) vulnerability in index.php in ExpressionEngine 1.2.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the URL parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0202">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:expressionengine:expressionengine:1.2.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:expressionengine:expressionengine:1.2.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0202</vuln:cve-id>
        <vuln:published-datetime>2008-01-09T19:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-10-22T01:44:13.657-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-10T13:02:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-94" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27128">27128</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/485786/100/0/threaded">20080103 securityvulns.com russian vulnerabilities digest</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://websecurity.com.ua/1454/">http://websecurity.com.ua/1454/</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityvulns.ru/Sdocument472.html">http://securityvulns.ru/Sdocument472.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FULLDISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html">20080103 securityvulns.com russian vulnerabilities digest</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/3539">3539</vuln:reference>
        </vuln:references>
        <vuln:summary>CRLF injection vulnerability in index.php in ExpressionEngine 1.2.1 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the URL parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0203">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:wordpress:cryptographp:1.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:wordpress:cryptographp:1.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0203</vuln:cve-id>
        <vuln:published-datetime>2008-01-09T19:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:27.857-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-10T13:06:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-79" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/485786/100/0/threaded">20080103 securityvulns.com russian vulnerabilities digest</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://websecurity.com.ua/1596/">http://websecurity.com.ua/1596/</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FULLDISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html">20080103 securityvulns.com russian vulnerabilities digest</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/3539">3539</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in cryptographp/admin.php in the Cryptographp 1.2 and earlier plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) cryptwidth, (2) cryptheight, (3) bgimg, (4) charR, (5) charG, (6) charB, (7) charclear, (8) tfont, (9) charel, (10) charelc, (11) charelv, (12) charnbmin, (13) charnbmax, (14) charspace, (15) charsizemin, (16) charsizemax, (17) charanglemax, (18) noisepxmin, (19) noisepxmax, (20) noiselinemin, (21) noiselinemax, (22) nbcirclemin, (23) nbcirclemax, or (24) brushsize parameter to wp-admin/options-general.php.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0204">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:wordpress:math_comment_spam_protection_plugin:2.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:wordpress:math_comment_spam_protection_plugin:2.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0204</vuln:cve-id>
        <vuln:published-datetime>2008-01-09T19:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:27.997-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-10T13:08:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-79" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/485786/100/0/threaded">20080103 securityvulns.com russian vulnerabilities digest</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://websecurity.com.ua/1576/">http://websecurity.com.ua/1576/</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FULLDISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html">20080103 securityvulns.com russian vulnerabilities digest</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/3539">3539</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in math-comment-spam-protection.php in the Math Comment Spam Protection 2.1 and earlier plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) mcsp_opt_msg_no_answer or (2) mcsp_opt_msg_wrong_answer parameter to wp-admin/options-general.php.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0205">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:wordpress:math_comment_spam_protection_plugin:2.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:wordpress:math_comment_spam_protection_plugin:2.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0205</vuln:cve-id>
        <vuln:published-datetime>2008-01-09T19:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:28.153-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-10T13:09:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-79" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/485786/100/0/threaded">20080103 securityvulns.com russian vulnerabilities digest</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://websecurity.com.ua/1576/">http://websecurity.com.ua/1576/</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FULLDISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html">20080103 securityvulns.com russian vulnerabilities digest</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/3539">3539</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple cross-site request forgery (CSRF) vulnerabilities in math-comment-spam-protection.php in the Math Comment Spam Protection 2.1 and earlier plugin for WordPress allow remote attackers to perform actions as administrators via the (1) mcsp_opt_msg_no_answer or (2) mcsp_opt_msg_wrong_answer parameter to wp-admin/options-general.php.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0206">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:wordpress:captcha:2.5d" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:wordpress:captcha:2.5d</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0206</vuln:cve-id>
        <vuln:published-datetime>2008-01-09T19:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:28.297-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-10T13:10:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-79" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/485786/100/0/threaded">20080103 securityvulns.com russian vulnerabilities digest</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://websecurity.com.ua/1588/">http://websecurity.com.ua/1588/</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FULLDISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html">20080103 securityvulns.com russian vulnerabilities digest</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/3539">3539</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in captcha\captcha.php in the Captcha! 2.5d and earlier plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) captcha_ttffolder, (2) captcha_numchars, (3) captcha_ttfrange, or (4) captcha_secret parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0207">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:pro_search:pro_search:0.17" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:pro_search:pro_search:0.17</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0207</vuln:cve-id>
        <vuln:published-datetime>2008-01-09T19:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:28.450-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-10T13:11:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-79" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27126">27126</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/485786/100/0/threaded">20080103 securityvulns.com russian vulnerabilities digest</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://websecurity.com.ua/1259/">http://websecurity.com.ua/1259/</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://sourceforge.net/project/shownotes.php?release_id=563784&amp;group_id=149797">http://sourceforge.net/project/shownotes.php?release_id=563784&amp;group_id=149797</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityvulns.ru/Sdocument731.html">http://securityvulns.ru/Sdocument731.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28335">28335</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FULLDISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html">20080103 securityvulns.com russian vulnerabilities digest</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/3539">3539</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in PRO-Search 0.17 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) prot, (2) host, (3) path, (4) name, (5) ext, (6) size, (7) search_days, or (8) show_page parameter to the default URI.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0208">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:snitz_forums_2000:snitz_forums:3.4.05" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:snitz_forums_2000:snitz_forums:3.4.05</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0208</vuln:cve-id>
        <vuln:published-datetime>2008-01-09T19:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-09-11T01:17:45.593-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-10T13:12:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-79" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27162">27162</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/485836/100/200/threaded">20080107 [HSC] Snitz Forums Multiple Vulnerabilities</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.packetstormsecurity.org/0801-exploits/snitz-multi.txt">http://www.packetstormsecurity.org/0801-exploits/snitz-multi.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28284">28284</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://hackerscenter.com/archive/view.asp?id=28145">http://hackerscenter.com/archive/view.asp?id=28145</vuln:reference>
        </vuln:references>
        <vuln:summary>Cross-site scripting (XSS) vulnerability in login.asp in Snitz Forums 2000 3.4.05 and earlier allows remote attackers to inject arbitrary web script or HTML via the target parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0209">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:snitz_forums_2000:snitz_forums:3.4.06" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:snitz_forums_2000:snitz_forums:3.4.06</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0209</vuln:cve-id>
        <vuln:published-datetime>2008-01-09T19:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-09-11T01:17:45.813-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>5.8</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-10T13:14:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-59" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/485836/100/200/threaded">20080107 [HSC] Snitz Forums Multiple Vulnerabilities</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.packetstormsecurity.org/0801-exploits/snitz-multi.txt">http://www.packetstormsecurity.org/0801-exploits/snitz-multi.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://hackerscenter.com/archive/view.asp?id=28145">http://hackerscenter.com/archive/view.asp?id=28145</vuln:reference>
        </vuln:references>
        <vuln:summary>Open redirect vulnerability in Forums/login.asp in Snitz Forums 2000 3.4.06 and earlier allows remote attackers to redirect users to arbitrary web sites via a URL in the target parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0210">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:uebimiau:webmail:2.7.10" />
                <cpe-lang:fact-ref name="cpe:/a:uebimiau:webmail:2.7.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:uebimiau:webmail:2.7.10</vuln:product>
            <vuln:product>cpe:/a:uebimiau:webmail:2.7.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0210</vuln:cve-id>
        <vuln:published-datetime>2008-01-09T19:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:28.903-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>6.4</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-10T13:14:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-287" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27154">27154</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/4846">4846</vuln:reference>
        </vuln:references>
        <vuln:summary>Uebimiau Webmail 2.7.10 and 2.7.2 does not protect authentication state variables from being set through HTTP requests, which allows remote attackers to bypass authentication via a sess[auth]=1 parameter settting.  NOTE: this can be leveraged to conduct directory traversal attacks without authentication by using CVE-2008-0140.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0127">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:mcafee:e-business_server:8.5.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:mcafee:e-business_server:8.5.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0127</vuln:cve-id>
        <vuln:published-datetime>2008-01-09T19:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:17.060-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>8.8</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-10T11:17:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-119" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27197">27197</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/486035/100/0/threaded">20080109 [INFIGO-2008-01-06]: McAfee E-Business Server Remote Preauth Code Execution / DoS - Corrected</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/485992/100/0/threaded">20080109 [INFIGO 2008-01-06]: McAfee E-Business Server Remote Preauth Code Execution / DoS</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://knowledge.mcafee.com/SupportSite/dynamickc.do?externalId=614472&amp;sliceId=SAL_Public&amp;command=show&amp;forward=nonthreadedKC&amp;kcId=614472">https://knowledge.mcafee.com/SupportSite/dynamickc.do?externalId=614472&amp;sliceId=SAL_Public&amp;command=show&amp;forward=nonthreadedKC&amp;kcId=614472</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39563">mcafee-ebusiness-packet-code-execution(39563)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39561">mcafee-ebusiness-authentication-packet-dos(39561)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/4878">4878</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/0087">ADV-2008-0087</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1019170">1019170</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/3530">3530</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28408">28408</vuln:reference>
        </vuln:references>
        <vuln:summary>The administration interface in McAfee E-Business Server 8.5.2 and earlier allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a long initial authentication packet.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0218">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:merak:icewarp_mail_server" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:merak:icewarp_mail_server</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0218</vuln:cve-id>
        <vuln:published-datetime>2008-01-10T18:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:30.217-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-11T09:42:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-79" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39564">icewarpmailserver-index-xss(39564)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/data/vulnerabilities/exploits/27189.html">http://www.securityfocus.com/data/vulnerabilities/exploits/27189.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27189">27189</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/0135">ADV-2008-0135</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28460">28460</vuln:reference>
        </vuln:references>
        <vuln:summary>Cross-site scripting (XSS) vulnerability in admin/index.html in Merak IceWarp Mail Server allows remote attackers to inject arbitrary web script or HTML via the message parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0219">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:php_webquest:php_webquest:2.6" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:php_webquest:php_webquest:2.6</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0219</vuln:cve-id>
        <vuln:published-datetime>2008-01-10T18:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-10-11T01:48:43.637-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-11T09:47:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-89" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39560">webquest-soportehorizontalw-sql-injection(39560)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27192">27192</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/4867">4867</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/26821">26821</vuln:reference>
        </vuln:references>
        <vuln:summary>SQL injection vulnerability in soporte_horizontal_w.php in PHP Webquest 2.6 allows remote attackers to execute arbitrary SQL commands via the id_actividad parameter, a different vector than CVE-2007-4920.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0220">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:gateway:cweblaunchctl_activex_control:1.0.0.1" />
                <cpe-lang:fact-ref name="cpe:/a:gateway:weblaunch" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:gateway:cweblaunchctl_activex_control:1.0.0.1</vuln:product>
            <vuln:product>cpe:/a:gateway:weblaunch</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0220</vuln:cve-id>
        <vuln:published-datetime>2008-01-10T18:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-09-15T01:10:42.640-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-11T10:01:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-119" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT-VN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/735441">VU#735441</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27193">27193</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/4982">4982</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/4869">4869</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/0077">ADV-2008-0077</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28379">28379</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FULLDISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=full-disclosure&amp;m=119984138526735&amp;w=2">20080109 Gateway WebLaunch ActiveX Control Insecure Method</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple stack-based buffer overflows in the WebLaunch.WeblaunchCtl.1 (aka CWebLaunchCtl) ActiveX control in weblaunch.ocx 1.0.0.1 in Gateway Weblaunch allow remote attackers to execute arbitrary code via a long string in the (1) second or (2) fourth argument to the DoWebLaunch method.  NOTE: some of these details are obtained from third party information.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0221">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:gateway:weblaunch:1.0.0.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:gateway:weblaunch:1.0.0.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0221</vuln:cve-id>
        <vuln:published-datetime>2008-01-10T18:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:30.670-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>9.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-11T10:04:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:cwe id="CWE-22" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/4869">4869</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/0077">ADV-2008-0077</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28379">28379</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FULLDISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=full-disclosure&amp;m=119984138526735&amp;w=2">20080109 Gateway WebLaunch ActiveX Control Insecure Method</vuln:reference>
        </vuln:references>
        <vuln:summary>Directory traversal vulnerability in the WebLaunch.WeblaunchCtl.1 (aka CWebLaunchCtl) ActiveX control in weblaunch.ocx 1.0.0.1 in Gateway Weblaunch allows remote attackers to execute arbitrary programs via a ..\ (dot dot backslash) in the second argument to the DoWebLaunch method.  NOTE: some of these details are obtained from third party information.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0222">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:wordpress:filemanager:1.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:wordpress:filemanager:1.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0222</vuln:cve-id>
        <vuln:published-datetime>2008-01-10T18:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:30.810-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-11T10:05:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-94" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39462">wordpress-wpfilemanager-file-upload(39462)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27151">27151</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/4844">4844</vuln:reference>
        </vuln:references>
        <vuln:summary>Unrestricted file upload vulnerability in ajaxfilemanager.php in the Wp-FileManager 1.2 plugin for WordPress allows remote attackers to upload and execute arbitrary PHP code via unspecified vectors.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0223">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:justsystem:ichitaro:11.0" />
                <cpe-lang:fact-ref name="cpe:/a:justsystem:ichitaro:12.0" />
                <cpe-lang:fact-ref name="cpe:/a:justsystem:ichitaro:13.0" />
                <cpe-lang:fact-ref name="cpe:/a:justsystem:ichitaro:2004" />
                <cpe-lang:fact-ref name="cpe:/a:justsystem:ichitaro:2005" />
                <cpe-lang:fact-ref name="cpe:/a:justsystem:ichitaro:2006" />
                <cpe-lang:fact-ref name="cpe:/a:justsystem:ichitaro:2007" />
                <cpe-lang:fact-ref name="cpe:/a:justsystem:ichitaro:linux" />
                <cpe-lang:fact-ref name="cpe:/a:justsystem:ichitaro_lite2" />
                <cpe-lang:fact-ref name="cpe:/a:justsystem:ichitaro_viewer" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:justsystem:ichitaro:linux</vuln:product>
            <vuln:product>cpe:/a:justsystem:ichitaro:12.0</vuln:product>
            <vuln:product>cpe:/a:justsystem:ichitaro_viewer</vuln:product>
            <vuln:product>cpe:/a:justsystem:ichitaro:11.0</vuln:product>
            <vuln:product>cpe:/a:justsystem:ichitaro_lite2</vuln:product>
            <vuln:product>cpe:/a:justsystem:ichitaro:2007</vuln:product>
            <vuln:product>cpe:/a:justsystem:ichitaro:2006</vuln:product>
            <vuln:product>cpe:/a:justsystem:ichitaro:2005</vuln:product>
            <vuln:product>cpe:/a:justsystem:ichitaro:2004</vuln:product>
            <vuln:product>cpe:/a:justsystem:ichitaro:13.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0223</vuln:cve-id>
        <vuln:published-datetime>2008-01-10T18:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:30.967-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>9.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-11T10:08:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:cwe id="CWE-119" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39501">justsystems-jsfc-bo(39501)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1019168">1019168</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27153">27153</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.justsystems.com/jp/info/pd8001.html">http://www.justsystems.com/jp/info/pd8001.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/0045">ADV-2008-0045</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.fourteenforty.jp/research/advisory.cgi?FFRRA-20080107">http://www.fourteenforty.jp/research/advisory.cgi?FFRRA-20080107</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28275">28275</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>JVN</vuln:source>
            <vuln:reference xml:lang="en" href="http://jvn.jp/jp/JVN%2308237857/index.html">JVN#08237857</vuln:reference>
        </vuln:references>
        <vuln:summary>Buffer overflow in JustSystems JSFC.DLL, as used in multiple JustSystems products such as Ichitaro, allows remote attackers to execute arbitrary code via a crafted .JTD file.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0224">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:runcms:runcms:1.5.3" />
                <cpe-lang:fact-ref name="cpe:/a:runcms:runcms:1.6" />
                <cpe-lang:fact-ref name="cpe:/a:runcms:runcms:1.6.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:runcms:runcms:1.6</vuln:product>
            <vuln:product>cpe:/a:runcms:runcms:1.6.1</vuln:product>
            <vuln:product>cpe:/a:runcms:runcms:1.5.3</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0224</vuln:cve-id>
        <vuln:published-datetime>2008-01-10T18:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:31.137-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-11T10:09:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-89" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39478">runcms-newbb-client-sql-injection(39478)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27152">27152</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28340">28340</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://milw0rm.com/exploits/4845">4845</vuln:reference>
        </vuln:references>
        <vuln:summary>SQL injection vulnerability in index.php in the Newbb_plus 0.92 and earlier module in RunCMS 1.6.1 allows remote attackers to execute arbitrary SQL commands via the Client-Ip parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0225">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:xine:xine-lib:1.1.9" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:xine:xine-lib:1.1.9</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0225</vuln:cve-id>
        <vuln:published-datetime>2008-01-10T18:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T21:04:50.210-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>6.4</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-11T10:11:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-119" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00592.html">FEDORA-2008-0718</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://bugzilla.redhat.com/show_bug.cgi?id=428620">https://bugzilla.redhat.com/show_bug.cgi?id=428620</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>UBUNTU</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ubuntu.com/usn/usn-635-1">USN-635-1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27198">27198</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/0163">ADV-2008-0163</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://sourceforge.net/project/shownotes.php?release_id=567872">http://sourceforge.net/project/shownotes.php?release_id=567872</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/31393">31393</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28489">28489</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28384">28384</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://aluigi.altervista.org/adv/xinermffhof-adv.txt">http://aluigi.altervista.org/adv/xinermffhof-adv.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.novell.com/linux/security/advisories/suse_security_summary_report.html">SUSE-SR:2008:002</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDVSA-2008:045">MDVSA-2008:045</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDVSA-2008:020">MDVSA-2008:020</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2008/dsa-1472">DSA-1472</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://security.gentoo.org/glsa/glsa-200801-12.xml">GLSA-200801-12</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28955">28955</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28674">28674</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28636">28636</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28507">28507</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://bugs.gentoo.org/show_bug.cgi?id=205197">http://bugs.gentoo.org/show_bug.cgi?id=205197</vuln:reference>
        </vuln:references>
        <vuln:summary>Heap-based buffer overflow in the rmff_dump_cont function in input/libreal/rmff.c in xine-lib 1.1.9 and earlier allows remote attackers to execute arbitrary code via the SDP Abstract attribute in an RTSP session, related to the rmff_dump_header function and related to disregarding the max field.  NOTE: some of these details are obtained from third party information.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0226">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:mysql:mysql" />
                <cpe-lang:fact-ref name="cpe:/a:yassl:yassl:1.7.5" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:yassl:yassl:1.7.5</vuln:product>
            <vuln:product>cpe:/a:mysql:mysql</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0226</vuln:cve-id>
        <vuln:published-datetime>2008-01-10T18:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-10-23T01:56:25.440-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-11T10:12:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-119" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39431">yassl-inputbufferoperator-bo(39431)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39429">yassl-processoldclienthello-bo(39429)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/31681">31681</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27140">27140</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/485811/100/0/threaded">20080104 Pre-auth buffer-overflow in mySQL through yaSSL</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/485810/100/0/threaded">20080104 Multiple vulnerabilities in yaSSL 1.7.5</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDVSA-2008:150">MDVSA-2008:150</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/2780">ADV-2008-2780</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://support.apple.com/kb/HT3216">http://support.apple.com/kb/HT3216</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/32222">32222</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28324">28324</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>APPLE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.html">APPLE-SA-2008-10-09</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>UBUNTU</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ubuntu.com/usn/usn-588-1">USN-588-1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/0560/references">ADV-2008-0560</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2008/dsa-1478">DSA-1478</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/3531">3531</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/29443">29443</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28597">28597</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28419">28419</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://dev.mysql.com/doc/refman/5.1/en/news-5-1-23.html">http://dev.mysql.com/doc/refman/5.1/en/news-5-1-23.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://bugs.mysql.com/33814">http://bugs.mysql.com/33814</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple buffer overflows in yaSSL 1.7.5 and earlier, as used in MySQL and possibly other products, allow remote attackers to execute arbitrary code via (1) the ProcessOldClientHello function in handshake.cpp or (2) "input_buffer&amp; operator>>" in yassl_imp.cpp.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0227">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:yassl:yassl:1.7.5" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:yassl:yassl:1.7.5</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0227</vuln:cve-id>
        <vuln:published-datetime>2008-01-10T18:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-10-23T01:56:25.910-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-11T10:13:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:cwe id="CWE-119" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39433">yassl-hashwithtransformupdate-dos(39433)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/31681">31681</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27140">27140</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/485810/100/0/threaded">20080104 Multiple vulnerabilities in yaSSL 1.7.5</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDVSA-2008:150">MDVSA-2008:150</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/2780">ADV-2008-2780</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://support.apple.com/kb/HT3216">http://support.apple.com/kb/HT3216</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/32222">32222</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28324">28324</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>APPLE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.html">APPLE-SA-2008-10-09</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>UBUNTU</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ubuntu.com/usn/usn-588-1">USN-588-1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/0560/references">ADV-2008-0560</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2008/dsa-1478">DSA-1478</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/3531">3531</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/29443">29443</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28597">28597</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://dev.mysql.com/doc/refman/5.1/en/news-5-1-23.html">http://dev.mysql.com/doc/refman/5.1/en/news-5-1-23.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://bugs.mysql.com/33814">http://bugs.mysql.com/33814</vuln:reference>
        </vuln:references>
        <vuln:summary>yaSSL 1.7.5 and earlier, as used in MySQL and possibly other products, allows remote attackers to cause a denial of service (crash) via a Hello packet containing a large size value, which triggers a buffer over-read in the HASHwithTransform::Update function in hash.cpp.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0228">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/h:linksys:wrt54gl:4.30.9" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/h:linksys:wrt54gl:4.30.9</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0228</vuln:cve-id>
        <vuln:published-datetime>2008-01-10T18:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:31.733-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>9.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-11T10:18:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:cwe id="CWE-352" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39502">linksys-apply-csrf(39502)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/485853/100/0/threaded">20080107 Linksys WRT54 GL - Session riding (CSRF)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28364">28364</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/486362/100/0/threaded">20080115 Re: Linksys WRT54 GL - Session riding (CSRF)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/3534">3534</vuln:reference>
        </vuln:references>
        <vuln:summary>Cross-site request forgery (CSRF) vulnerability in apply.cgi in the Linksys WRT54GL Wireless-G Broadband Router with firmware 4.30.9 allows remote attackers to perform actions as administrators.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0229">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:level_one:wbr-3460a:1.0.11" />
                <cpe-lang:fact-ref name="cpe:/a:level_one:wbr-3460a:1.0.12" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:level_one:wbr-3460a:1.0.11</vuln:product>
            <vuln:product>cpe:/a:level_one:wbr-3460a:1.0.12</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0229</vuln:cve-id>
        <vuln:published-datetime>2008-01-10T18:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:31.873-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>10.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-11T10:16:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-287" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1019162">1019162</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27183">27183</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/485935/100/0/threaded">20080108 Level-One WBR-3460A Grants Root Access</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/3533">3533</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28397">28397</vuln:reference>
        </vuln:references>
        <vuln:summary>The telnet service in LevelOne WBR-3460 4-Port ADSL 2/2+ Wireless Modem Router with firmware 1.00.11 and 1.00.12 does not require authentication, which allows remote attackers on the local or wireless network to obtain administrative access.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0230">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:osdate:osdate:2.0.8" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:osdate:osdate:2.0.8</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0230</vuln:cve-id>
        <vuln:published-datetime>2008-01-10T19:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:32.030-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-11T10:19:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-94" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39567">osdate-php121db-file-include(39567)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27208">27208</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://packetstormsecurity.org/0801-exploits/osdata-lfi.txt">http://packetstormsecurity.org/0801-exploits/osdata-lfi.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/4870">4870</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28420">28420</vuln:reference>
        </vuln:references>
        <vuln:summary>PHP remote file inclusion vulnerability in php121db.php in osDate 2.0.8 and possibly earlier versions allows remote attackers to execute arbitrary PHP code via a URL in the php121dir parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0231">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:tuned_studios:classic_theme" />
                <cpe-lang:fact-ref name="cpe:/a:tuned_studios:endless" />
                <cpe-lang:fact-ref name="cpe:/a:tuned_studios:freeze_theme" />
                <cpe-lang:fact-ref name="cpe:/a:tuned_studios:lonely_maple" />
                <cpe-lang:fact-ref name="cpe:/a:tuned_studios:music_theme" />
                <cpe-lang:fact-ref name="cpe:/a:tuned_studios:orange_cutout" />
                <cpe-lang:fact-ref name="cpe:/a:tuned_studios:subwoofer" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:tuned_studios:subwoofer</vuln:product>
            <vuln:product>cpe:/a:tuned_studios:endless</vuln:product>
            <vuln:product>cpe:/a:tuned_studios:orange_cutout</vuln:product>
            <vuln:product>cpe:/a:tuned_studios:lonely_maple</vuln:product>
            <vuln:product>cpe:/a:tuned_studios:freeze_theme</vuln:product>
            <vuln:product>cpe:/a:tuned_studios:classic_theme</vuln:product>
            <vuln:product>cpe:/a:tuned_studios:music_theme</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0231</vuln:cve-id>
        <vuln:published-datetime>2008-01-10T19:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:32.187-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-11T10:20:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:cwe id="CWE-22" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39555">tunedstudiostemplates-index-file-include(39555)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27196">27196</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/485991/100/0/threaded">20080109 LFI in Tuned Studios Templates</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/4876">4876</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/3532">3532</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple directory traversal vulnerabilities in index.php in Tuned Studios (1) Subwoofer, (2) Freeze Theme, (3) Orange Cutout, (4) Lonely Maple, (5) Endless, (6) Classic Theme, and (7) Music Theme webpage templates allow remote attackers to include and execute arbitrary files via ".." sequences in the page parameter.  NOTE: this can be leveraged for remote file inclusion when running in some PHP 5 environments.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0232">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:zero_cms:zero_cms:1.0_alpha" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:zero_cms:zero_cms:1.0_alpha</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0232</vuln:cve-id>
        <vuln:published-datetime>2008-01-10T19:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:32.340-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-11T10:23:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-89" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39530">zerocms-index-sql-injection(39530)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27186">27186</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://packetstormsecurity.org/0801-exploits/zerocms-sql.txt">http://packetstormsecurity.org/0801-exploits/zerocms-sql.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/4864">4864</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple SQL injection vulnerabilities in Zero CMS 1.0 Alpha allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to index.php, or the (2) f or t parameters to forums/index.php.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0233">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:zero_cms:zero_cms:1.0_alpha" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:zero_cms:zero_cms:1.0_alpha</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0233</vuln:cve-id>
        <vuln:published-datetime>2008-01-10T21:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:32.497-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-11T10:27:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-264" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://packetstormsecurity.org/0801-exploits/zerocms-sql.txt">http://packetstormsecurity.org/0801-exploits/zerocms-sql.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/4864">4864</vuln:reference>
        </vuln:references>
        <vuln:summary>Unrestricted file upload vulnerability in Zero CMS 1.0 Alpha and earlier allows remote attackers to bypass intended access restrictions and upload and execute arbitrary files by uploading an avatar file with an accepted Content-Type such as image/jpeg.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0234">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.3.1.70" />
                <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.4" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:apple:quicktime:7.3.1.70</vuln:product>
            <vuln:product>cpe:/a:apple:quicktime:7.4</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0234</vuln:cve-id>
        <vuln:published-datetime>2008-01-10T21:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-02-26T00:00:00.000-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>9.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-11T10:31:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-119" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT-VN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/112179">VU#112179</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/2064/references">ADV-2008-2064</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/0107">ADV-2008-0107</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>APPLE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.apple.com/archives/security-announce/2008//Jul/msg00000.html">APPLE-SA-2008-07-10</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39601">quicktime-rtsp-responses-bo(39601)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1019178">1019178</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27225">27225</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/486268/100/0/threaded">20080112 Re: Buffer-overflow in Quicktime Player 7.3.1.70</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/486241/100/0/threaded">20080112 Re: Re: Buffer-overflow in Quicktime Player 7.3.1.70</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/486238/100/0/threaded">20080114 Re: [Full-disclosure] Buffer-overflow in Quicktime Player 7.3.1.70</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/486174/100/0/threaded">20080111 Re: Buffer-overflow in Quicktime Player 7.3.1.70</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/486161/100/0/threaded">20080111 Re: Re: Buffer-overflow in Quicktime Player 7.3.1.70</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/486114/100/0/threaded">20080110 Re: Buffer-overflow in Quicktime Player 7.3.1.70</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/486091/100/0/threaded">20080110 Buffer-overflow in Quicktime Player 7.3.1.70</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/4906">4906</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/4885">4885</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/3537">3537</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/31034">31034</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28423">28423</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>APPLE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.apple.com/archives/security-announce/2008/Feb/msg00001.html">APPLE-SA-2008-02-06</vuln:reference>
        </vuln:references>
        <vuln:summary>Buffer overflow in Apple Quicktime Player 7.3.1.70 and other versions before 7.4.1, when RTSP tunneling is enabled, allows remote attackers to execute arbitrary code via a long Reason-Phrase response to an rtsp:// request, as demonstrated using a 404 error message.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0235">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:microsoft:vfp_ole_server_activex_control" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:microsoft:vfp_ole_server_activex_control</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0235</vuln:cve-id>
        <vuln:published-datetime>2008-01-10T21:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:32.793-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>10.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-11T10:37:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-94" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39559">microsoft-vfpoleserver-command-execution(39559)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27199">27199</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://shinnai.altervista.org/exploits/txt/TXT_rNowA1916DKFNUF48NyS.html">http://shinnai.altervista.org/exploits/txt/TXT_rNowA1916DKFNUF48NyS.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/4875">4875</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28417">28417</vuln:reference>
        </vuln:references>
        <vuln:summary>The Microsoft VFP_OLE_Server ActiveX control allows remote attackers to execute arbitrary code by invoking the foxcommand method.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0236">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:microsoft:visual_foxpro:6.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:microsoft:visual_foxpro:6.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0236</vuln:cve-id>
        <vuln:published-datetime>2008-01-10T21:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:32.937-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>5.8</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-11T10:35:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39558">microsoft-foxserver-command-execution(39558)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27205">27205</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://shinnai.altervista.org/exploits/txt/TXT_DiWu9j82RCq4zpaQAoxn.html">http://shinnai.altervista.org/exploits/txt/TXT_DiWu9j82RCq4zpaQAoxn.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/4873">4873</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28417">28417</vuln:reference>
        </vuln:references>
        <vuln:summary>An ActiveX control for Microsoft Visual FoxPro (vfp6r.dll 6.0.8862.0) allows remote attackers to execute arbitrary commands by invoking the DoCmd method.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0237">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:microsoft:rich_textbox_control:6.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:microsoft:rich_textbox_control:6.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0237</vuln:cve-id>
        <vuln:published-datetime>2008-01-10T21:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:33.090-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>6.8</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-11T10:37:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:cwe id="CWE-20" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39557">microsoft-richtextbox-file-overwrite(39557)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27201">27201</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://shinnai.altervista.org/exploits/txt/TXT_DZVN8CwCha0I2fI3NeEs.html">http://shinnai.altervista.org/exploits/txt/TXT_DZVN8CwCha0I2fI3NeEs.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/4874">4874</vuln:reference>
        </vuln:references>
        <vuln:summary>The Microsoft Rich Textbox ActiveX Control (RICHTX32.OCX) 6.1.97.82 allows remote attackers to execute arbitrary commands by invoking the insecure SaveFile method.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0238">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:xine:xine-lib:1.1.9" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:xine:xine-lib:1.1.9</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0238</vuln:cve-id>
        <vuln:published-datetime>2008-01-11T16:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-10T21:04:51.210-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-14T08:29:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-119" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>UBUNTU</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ubuntu.com/usn/usn-635-1">USN-635-1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/31393">31393</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28384">28384</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDVSA-2008:045">MDVSA-2008:045</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDVSA-2008:020">MDVSA-2008:020</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://security.gentoo.org/glsa/glsa-200801-12.xml">GLSA-200801-12</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28955">28955</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28674">28674</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://bugs.gentoo.org/show_bug.cgi?id=205197">http://bugs.gentoo.org/show_bug.cgi?id=205197</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple heap-based buffer overflows in the rmff_dump_cont function in input/libreal/rmff.c in xine-lib 1.1.9 allow remote attackers to execute arbitrary code via the SDP (1) Title, (2) Author, or (3) Copyright attribute, related to the rmff_dump_header function, different vectors than CVE-2008-0225.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0239">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:sun:java_system_identity_manager:6.0:sp1" />
                <cpe-lang:fact-ref name="cpe:/a:sun:java_system_identity_manager:6.0:sp2" />
                <cpe-lang:fact-ref name="cpe:/a:sun:java_system_identity_manager:6.0:sp3" />
                <cpe-lang:fact-ref name="cpe:/a:sun:java_system_identity_manager:7.0" />
                <cpe-lang:fact-ref name="cpe:/a:sun:java_system_identity_manager:7.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:sun:java_system_identity_manager:6.0:sp1</vuln:product>
            <vuln:product>cpe:/a:sun:java_system_identity_manager:6.0:sp2</vuln:product>
            <vuln:product>cpe:/a:sun:java_system_identity_manager:6.0:sp3</vuln:product>
            <vuln:product>cpe:/a:sun:java_system_identity_manager:7.0</vuln:product>
            <vuln:product>cpe:/a:sun:java_system_identity_manager:7.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0239</vuln:cve-id>
        <vuln:published-datetime>2008-01-11T17:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-11-19T01:43:07.297-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-14T08:34:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-79" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/486076/100/0/threaded">20080110 PR07-06, PR07-07, PR07-08, PR07-09, PR07-10, PR07-12: Several XSS, Cross-domain Redirection and Frame Injection on Sun Java System Identity Manager</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.procheckup.com/Vulnerability_PR07-08.php">http://www.procheckup.com/Vulnerability_PR07-08.php</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.procheckup.com/Vulnerability_PR07-07.php">http://www.procheckup.com/Vulnerability_PR07-07.php</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.procheckup.com/Vulnerability_PR07-06.php">http://www.procheckup.com/Vulnerability_PR07-06.php</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39583">sun-identity-main-xss(39583)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39582">sun-identity-resultsform-xss(39582)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39581">sun-identity-lang-xss(39581)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39580">sun-identity-login-xss(39580)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27214">27214</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.procheckup.com/Vulnerability_PR07-09.php">http://www.procheckup.com/Vulnerability_PR07-09.php</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/0089">ADV-2008-0089</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-103180-1">103180</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28356">28356</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1019175">1019175</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-66-200558-1">200558</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/3535">3535</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager 6.0 SP1 through SP3, 7.0, and 7.1 allow remote attackers to inject arbitrary HTML or web script via the (1) cntry or lang parameters to /idm/login.jsp, (2) resultsForm parameter to /idm/account/findForSelect.jsp, or (3) activeControl parameter to /idm/user/main.jsp.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0240">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:sun:java_system_identity_manager:6.0:sp1" />
                <cpe-lang:fact-ref name="cpe:/a:sun:java_system_identity_manager:6.0:sp2" />
                <cpe-lang:fact-ref name="cpe:/a:sun:java_system_identity_manager:6.0:sp3" />
                <cpe-lang:fact-ref name="cpe:/a:sun:java_system_identity_manager:7.0" />
                <cpe-lang:fact-ref name="cpe:/a:sun:java_system_identity_manager:7.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:sun:java_system_identity_manager:6.0:sp1</vuln:product>
            <vuln:product>cpe:/a:sun:java_system_identity_manager:6.0:sp2</vuln:product>
            <vuln:product>cpe:/a:sun:java_system_identity_manager:6.0:sp3</vuln:product>
            <vuln:product>cpe:/a:sun:java_system_identity_manager:7.0</vuln:product>
            <vuln:product>cpe:/a:sun:java_system_identity_manager:7.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0240</vuln:cve-id>
        <vuln:published-datetime>2008-01-11T17:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:33.590-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-14T08:38:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-79" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.procheckup.com/Vulnerability_PR07-10.php">http://www.procheckup.com/Vulnerability_PR07-10.php</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39586">sun-identity-index-frame-injection(39586)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27214">27214</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/486076/100/0/threaded">20080110 PR07-06, PR07-07, PR07-08, PR07-09, PR07-10, PR07-12: Several XSS, Cross-domain Redirection and Frame Injection on Sun Java System Identity Manager</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/0089">ADV-2008-0089</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-103180-1">103180</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28356">28356</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-66-200558-1">200558</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/3535">3535</vuln:reference>
        </vuln:references>
        <vuln:summary>/idm/help/index.jsp in Sun Java System Identity Manager 6.0 SP1 through SP3, 7.0, and 7.1 allows remote attackers to inject frames from arbitrary web sites and conduct phishing attacks via the helpUrl parameter, aka "frame injection."</vuln:summary>
    </entry>
    <entry id="CVE-2008-0241">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:sun:java_system_identity_manager:6.0:sp1" />
                <cpe-lang:fact-ref name="cpe:/a:sun:java_system_identity_manager:6.0:sp2" />
                <cpe-lang:fact-ref name="cpe:/a:sun:java_system_identity_manager:6.0:sp3" />
                <cpe-lang:fact-ref name="cpe:/a:sun:java_system_identity_manager:7.0" />
                <cpe-lang:fact-ref name="cpe:/a:sun:java_system_identity_manager:7.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:sun:java_system_identity_manager:6.0:sp1</vuln:product>
            <vuln:product>cpe:/a:sun:java_system_identity_manager:6.0:sp2</vuln:product>
            <vuln:product>cpe:/a:sun:java_system_identity_manager:6.0:sp3</vuln:product>
            <vuln:product>cpe:/a:sun:java_system_identity_manager:7.0</vuln:product>
            <vuln:product>cpe:/a:sun:java_system_identity_manager:7.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0241</vuln:cve-id>
        <vuln:published-datetime>2008-01-11T17:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-02-04T00:00:00.000-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>5.8</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-14T08:39:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-20" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.procheckup.com/Vulnerability_PR07-12.php">http://www.procheckup.com/Vulnerability_PR07-12.php</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-66-200558-1">200558</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-103180-1">103180</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39590">sun-identity-login-security-bypass(39590)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27214">27214</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/486076/100/0/threaded">20080110 PR07-06, PR07-07, PR07-08, PR07-09, PR07-10, PR07-12: Several XSS, Cross-domain Redirection and Frame Injection on Sun Java System Identity Manager</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/0089">ADV-2008-0089</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/3535">3535</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28356">28356</vuln:reference>
        </vuln:references>
        <vuln:summary>Open redirect vulnerability in /idm/user/login.jsp in Sun Java System Identity Manager 6.0 SP1 through SP3, 7.0, and 7.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the nextPage parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0005">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:apache:http_server:1.3</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0005</vuln:cve-id>
        <vuln:published-datetime>2008-01-11T19:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-31T01:54:30.797-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-14T09:37:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-79" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00562.html">FEDORA-2008-1695</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00541.html">FEDORA-2008-1711</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39615">apache-modproxyftp-utf7-xss(39615)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>UBUNTU</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ubuntu.com/usn/usn-575-1">USN-575-1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1019185">1019185</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27234">27234</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/505990/100/0/threaded">20090821 VMSA-2009-0010 VMware Hosted products update libpng and Apache HTTP Server</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/486167/100/0/threaded">20080110 SecurityReason - Apache (mod_proxy_ftp) Undefined Charset UTF-7 XSS Vulnerability</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2008-0009.html">RHSA-2008:0009</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2008-0008.html">RHSA-2008:0008</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2008-0007.html">RHSA-2008:0007</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2008-0006.html">RHSA-2008:0006</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2008-0005.html">RHSA-2008:0005</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2008-0004.html">RHSA-2008:0004</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDVSA-2008:016">MDVSA-2008:016</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDVSA-2008:015">MDVSA-2008:015</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDVSA-2008:014">MDVSA-2008:014</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/1875/references">ADV-2008-1875</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/0924/references">ADV-2008-0924</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://support.avaya.com/elmodocs2/security/ASA-2008-032.htm">http://support.avaya.com/elmodocs2/security/ASA-2008-032.htm</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/3526">3526</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASONRES</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/achievement_securityalert/49">20080110 Apache (mod_proxy_ftp) Undefined Charset UTF-7 XSS Vulnerability</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://security.gentoo.org/glsa/glsa-200803-19.xml">GLSA-200803-19</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/35650">35650</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/30732">30732</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/29640">29640</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/29420">29420</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/29348">29348</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28977">28977</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28749">28749</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28607">28607</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28526">28526</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28471">28471</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28467">28467</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">SSRT090192</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">SSRT090192</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=bugtraq&amp;m=124654546101607&amp;w=2">SSRT090085</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=bugtraq&amp;m=124654546101607&amp;w=2">SSRT090085</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.vmware.com/pipermail/security-announce/2009/000062.html">[security-announce] 20090820 VMSA-2009-0010 VMware Hosted products update libpng and Apache HTTP Server</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00004.html">SUSE-SA:2008:021</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>APPLE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html">APPLE-SA-2008-03-18</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://docs.info.apple.com/article.html?artnum=307562">http://docs.info.apple.com/article.html?artnum=307562</vuln:reference>
        </vuln:references>
        <vuln:summary>mod_proxy_ftp in Apache 2.2.x before 2.2.7-dev, 2.0.x before 2.0.62-dev, and 1.3.x before 1.3.40-dev does not define a charset, which allows remote attackers to conduct cross-site scripting (XSS) attacks using UTF-7 encoding.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0123">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:moodle:moodle:1.8.3" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:moodle:moodle:1.8.3</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0123</vuln:cve-id>
        <vuln:published-datetime>2008-01-11T20:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:16.547-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-14T09:41:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-79" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://int21.de/cve/CVE-2008-0123-moodle.html">http://int21.de/cve/CVE-2008-0123-moodle.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FULLDISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://archives.neohapsis.com/archives/fulldisclosure/2008-01/0202.html">20080111 Cross site scripting (XSS) in Moodle 1.8.3</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39630">moodle-install-xss(39630)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27259">27259</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/486198/100/0/threaded">20080111 Cross site scripting (XSS) in Moodle 1.8.3</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/0164">ADV-2008-0164</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28838">28838</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00003.html">SUSE-SR:2008:003</vuln:reference>
        </vuln:references>
        <vuln:summary>Cross-site scripting (XSS) vulnerability in install.php for Moodle 1.8.3, and possibly other versions before 1.8.4, allows remote attackers to inject arbitrary web script or HTML via the dbname parameter.  NOTE: this issue only exists until the installation is complete.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0242">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:10.0::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:10.0::x86" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:sun:solaris:10.0::x86</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:10.0::sparc</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0242</vuln:cve-id>
        <vuln:published-datetime>2008-01-11T21:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:33.903-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-14T10:06:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:5211" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5211" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-103165-1">103165</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39629">solaris-libdevinfo-privilege-escalation(39629)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1019187">1019187</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27253">27253</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/0131">ADV-2008-0131</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-66-200641-1">200641</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28493">28493</vuln:reference>
        </vuln:references>
        <vuln:summary>Unspecified vulnerability in libdevinfo in Sun Solaris 10 allows local users to access files and gain privileges via unknown vectors, related to login device permissions.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0243">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:7.0" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:7.0.1" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:7.0.2" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:7.0.2::fp1" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:7.0.2::fp2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:ibm:lotus_domino:7.0.2</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:7.0.1</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:7.0.2::fp1</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:7.0.2::fp2</vuln:product>
            <vuln:product>cpe:/a:ibm:lotus_domino:7.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0243</vuln:cve-id>
        <vuln:published-datetime>2008-01-11T21:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:34.077-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.8</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-14T10:16:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39588">lotus-domino-unspecified-dos(39588)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27215">27215</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/0086">ADV-2008-0086</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www-1.ibm.com/support/docview.wss?uid=swg27011539">http://www-1.ibm.com/support/docview.wss?uid=swg27011539</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28411">28411</vuln:reference>
        </vuln:references>
        <vuln:summary>Unspecified vulnerability in Lotus Domino 7.0.2 before Fix Pack 3 allows attackers to cause a denial of service via unknown vectors.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0244">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:sap:maxdb:7.6.3_build_007" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:sap:maxdb:7.6.3_build_007</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0244</vuln:cve-id>
        <vuln:published-datetime>2008-01-11T21:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:34.233-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>10.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-14T10:16:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-20" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39573">maxdb-system-command-execution(39573)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1019171">1019171</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27206">27206</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/486039/100/0/threaded">20080109 Pre-auth remote commands execution in SAP MaxDB 7.6.03.07</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/4877">4877</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/0104">ADV-2008-0104</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28409">28409</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://aluigi.altervista.org/adv/sapone-adv.txt">http://aluigi.altervista.org/adv/sapone-adv.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/3536">3536</vuln:reference>
        </vuln:references>
        <vuln:summary>SAP MaxDB 7.6.03 build 007 and earlier allows remote attackers to execute arbitrary commands via "&amp;&amp;" and other shell metacharacters in exec_sdbinfo and other unspecified commands, which are executed when MaxDB invokes cons.exe.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0245">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:uploadscript:uploadimage:1.0" />
                <cpe-lang:fact-ref name="cpe:/a:uploadscript:uploadscript:1.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:uploadscript:uploadimage:1.0</vuln:product>
            <vuln:product>cpe:/a:uploadscript:uploadscript:1.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0245</vuln:cve-id>
        <vuln:published-datetime>2008-01-11T21:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:34.387-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-14T10:21:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-264" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39571">uploadimage-admin-command-execution(39571)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27203">27203</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/4871">4871</vuln:reference>
        </vuln:references>
        <vuln:summary>admin.php in UploadImage 1.0 does not check for the original password before making a change to a new password, which allows remote attackers to gain administrator privileges via the pass parameter in a nopass (Set Password) action.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0246">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:uploadscript:uploadimage:1.0" />
                <cpe-lang:fact-ref name="cpe:/a:uploadscript:uploadscript:1.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:uploadscript:uploadimage:1.0</vuln:product>
            <vuln:product>cpe:/a:uploadscript:uploadscript:1.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0246</vuln:cve-id>
        <vuln:published-datetime>2008-01-11T21:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:34.530-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>10.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-14T10:34:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:cwe id="CWE-264" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39570">uploadscript-admin-command-execution(39570)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27203">27203</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/4871">4871</vuln:reference>
        </vuln:references>
        <vuln:summary>admin.php in UploadScript 1.0 does not check for the original password before making a change to a new password, which allows remote attackers to gain administrator privileges via the pass parameter in a nopass (Set Password) action.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0247">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:ibm:tivoli_storage_manager_express:5.3" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:ibm:tivoli_storage_manager_express:5.3</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0247</vuln:cve-id>
        <vuln:published-datetime>2008-01-11T21:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:34.687-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>10.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-14T10:26:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:cwe id="CWE-119" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27235">27235</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www-1.ibm.com/support/docview.wss?uid=swg21291536">http://www-1.ibm.com/support/docview.wss?uid=swg21291536</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28440">28440</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39604">ibm-tsmexpressserver-bo(39604)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.zerodayinitiative.com/advisories/ZDI-08-001.html">http://www.zerodayinitiative.com/advisories/ZDI-08-001.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1019182">1019182</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/486270/100/0/threaded">20080114 ZDI-08-001: IBM Tivoli Storage Manager Express Backup Server Heap Overflow Vulnerability</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/0106">ADV-2008-0106</vuln:reference>
        </vuln:references>
        <vuln:summary>Heap-based buffer overflow in the Express Backup Server service (dsmsvc.exe) in IBM Tivoli Storage Manager (TSM) Express 5.3 before 5.3.7.3 allows remote attackers to execute arbitrary code via a packet with a large length value.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0248">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:streamaudio:chaincast_proxymanager_activex_control" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:streamaudio:chaincast_proxymanager_activex_control</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0248</vuln:cve-id>
        <vuln:published-datetime>2008-01-11T21:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:34.840-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>9.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-14T10:32:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-119" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39622">streamaudio-chaincastproxymanager-bo(39622)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27247">27247</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/4894">4894</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FULLDISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059572.html">20080111 StreamAudio ChainCast ProxyManager ccpm_0237.dll Buffer Overflow</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/0133">ADV-2008-0133</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28461">28461</vuln:reference>
        </vuln:references>
        <vuln:summary>Buffer overflow in an ActiveX control in ccpm_0237.dll for StreamAudio ChainCast ProxyManager allows remote attackers to execute arbitrary code via a long URL argument to the InternalTuneIn method.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0249">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:phpwebquest:phpwebquest:2.6" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:phpwebquest:phpwebquest:2.6</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0249</vuln:cve-id>
        <vuln:published-datetime>2008-01-11T21:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:34.983-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-14T10:39:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-200" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39572">phpwebquest-backup-information-disclosure(39572)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27202">27202</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/4872">4872</vuln:reference>
        </vuln:references>
        <vuln:summary>PHP Webquest 2.6 allows remote attackers to retrieve database credentials via a direct request to admin/backup_phpwebquest.php, which leaks the credentials in an error message if a call to /usr/bin/mysqldump fails.  NOTE: this might only be an issue in limited environments.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0250">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:microsoft:visual_interdev:6.0:sp6" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:microsoft:visual_interdev:6.0:sp6</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0250</vuln:cve-id>
        <vuln:published-datetime>2008-01-11T21:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:35.137-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>9.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-14T10:41:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-119" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27250">27250</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/4892">4892</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://shinnai.altervista.org/exploits/txt/TXT_PoEOrFM8py30PXrDF7IY.html">http://shinnai.altervista.org/exploits/txt/TXT_PoEOrFM8py30PXrDF7IY.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/41826">visualinterdev-sln-project-bo(41826)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28482">28482</vuln:reference>
        </vuln:references>
        <vuln:summary>Buffer overflow in Microsoft Visual InterDev 6.0 (SP6) allows user-assisted attackers to execute arbitrary code via a Studio Solution (.SLN) file with a long Project line.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0251">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:photopost:photopost_vbgallery:2.4.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:photopost:photopost_vbgallery:2.4.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0251</vuln:cve-id>
        <vuln:published-datetime>2008-01-11T21:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:35.277-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>10.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-14T10:44:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-94" />
        <vuln:cwe id="CWE-20" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39621">vbgallery-unspecified-code-execution(39621)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.photopost.com/forum/showthread.php?t=134910">http://www.photopost.com/forum/showthread.php?t=134910</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.photopost.com/forum/showthread.php?t=134909">http://www.photopost.com/forum/showthread.php?t=134909</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28430">28430</vuln:reference>
        </vuln:references>
        <vuln:summary>Unrestricted file upload vulnerability in PhotoPost vBGallery before 2.4.2 allows remote attackers to upload and execute arbitrary files via unknown vectors.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0252">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:cherrypy:cherrypy:2.1.0" />
                <cpe-lang:fact-ref name="cpe:/a:cherrypy:cherrypy:3.0.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:cherrypy:cherrypy:3.0.2</vuln:product>
            <vuln:product>cpe:/a:cherrypy:cherrypy:2.1.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0252</vuln:cve-id>
        <vuln:published-datetime>2008-01-11T21:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-10-17T01:28:08.177-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-14T10:48:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-22" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/0039">ADV-2008-0039</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cherrypy.org/changeset/1775">http://www.cherrypy.org/changeset/1775</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cherrypy.org/changeset/1774">http://www.cherrypy.org/changeset/1774</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00297.html">FEDORA-2008-0333</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00240.html">FEDORA-2008-0299</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://bugs.gentoo.org/show_bug.cgi?id=204829">https://bugs.gentoo.org/show_bug.cgi?id=204829</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cherrypy.org/ticket/744">http://www.cherrypy.org/ticket/744</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cherrypy.org/changeset/1776">http://www.cherrypy.org/changeset/1776</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28354">28354</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28353">28353</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://issues.rpath.com/browse/RPL-2127">https://issues.rpath.com/browse/RPL-2127</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27181">27181</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/487001/100/0/threaded">20080124 rPSA-2008-0030-1 CherryPy</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2008/dsa-1481">DSA-1481</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://security.gentoo.org/glsa/glsa-200801-11.xml">GLSA-200801-11</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28769">28769</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28620">28620</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28611">28611</vuln:reference>
        </vuln:references>
        <vuln:summary>Directory traversal vulnerability in the _get_file_path function in (1) lib/sessions.py in CherryPy 3.0.x up to 3.0.2, (2) filter/sessionfilter.py in CherryPy 2.1, and (3) filter/sessionfilter.py in CherryPy 2.x allows remote attackers to create or delete arbitrary files, and possibly read and write portions of arbitrary files, via a crafted session id in a cookie.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0253">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:binn:sbuilder" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:binn:sbuilder</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0253</vuln:cve-id>
        <vuln:published-datetime>2008-01-15T15:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:35.577-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-15T15:29:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-89" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27264">27264</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/4904">4904</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39634">binnsbuilder-fulltext-sql-injection(39634)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/486265/100/0/threaded">20080114 Binn SBuilder (nid) Remote Blind Sql Injection Vulnerabily</vuln:reference>
        </vuln:references>
        <vuln:summary>SQL injection vulnerability in full_text.php in Binn SBuilder allows remote attackers to execute arbitrary SQL commands via the nid parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0254">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:wavelink_media:tutorialcms:1.02" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:wavelink_media:tutorialcms:1.02</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0254</vuln:cve-id>
        <vuln:published-datetime>2008-01-15T15:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:35.733-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>6.8</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-15T15:31:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-89" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27263">27263</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/4901">4901</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28446">28446</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39642">tutorialcms-activate-sql-injection(39642)</vuln:reference>
        </vuln:references>
        <vuln:summary>SQL injection vulnerability in activate.php in TutorialCMS (aka Photoshop Tutorials) 1.02, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the userName parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0255">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:igamingcms:igaming_cms:1.5" />
                <cpe-lang:fact-ref name="cpe:/a:igamingcms:igaming_cms:1.3.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:igamingcms:igaming_cms:1.5</vuln:product>
            <vuln:product>cpe:/a:igamingcms:igaming_cms:1.3.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0255</vuln:cve-id>
        <vuln:published-datetime>2008-01-15T15:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:35.887-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-15T15:34:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-89" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39598">igamingcms-archive-sql-injection(39598)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27230">27230</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/4886">4886</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28426">28426</vuln:reference>
        </vuln:references>
        <vuln:summary>SQL injection vulnerability in archive.php in iGaming 1.5, and 1.3.1 and earlier, allows remote attackers to execute arbitrary SQL commands via the section parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0256">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:matteo_binda:asp_photo_gallery:1.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:matteo_binda:asp_photo_gallery:1.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0256</vuln:cve-id>
        <vuln:published-datetime>2008-01-15T15:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:36.027-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-15T15:37:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-89" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27262">27262</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/4900">4900</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28447">28447</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39646">aspphotogallery-multiple-sql-injection(39646)</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple SQL injection vulnerabilities in Matteo Binda ASP Photo Gallery 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to (a) Imgbig.asp, (b) thumb.asp, and (c) thumbricerca.asp and the (2) ricerca parameter to (d) thumbricerca.asp.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0257">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:dansie:search_engine:2.7" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:dansie:search_engine:2.7</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0257</vuln:cve-id>
        <vuln:published-datetime>2008-01-15T15:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:36.187-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-15T15:39:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-79" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28465">28465</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39636">dansiesearchengine-search-xss(39636)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27269">27269</vuln:reference>
        </vuln:references>
        <vuln:summary>Cross-site scripting (XSS) vulnerability in search.pl in Dansie Search Engine 2.7 allows remote attackers to inject arbitrary web script or HTML via the keywords parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0258">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:php_running_management:phprunman:1.0.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:php_running_management:phprunman:1.0.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0258</vuln:cve-id>
        <vuln:published-datetime>2008-01-15T15:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:36.340-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-15T15:42:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-79" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27268">27268</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://sourceforge.net/project/shownotes.php?release_id=568237&amp;group_id=103505">http://sourceforge.net/project/shownotes.php?release_id=568237&amp;group_id=103505</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28474">28474</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1204199&amp;group_id=103505&amp;atid=634992">http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1204199&amp;group_id=103505&amp;atid=634992</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39639">phprunningmanagement-index-xss(39639)</vuln:reference>
        </vuln:references>
        <vuln:summary>Cross-site scripting (XSS) vulnerability in index.php in PHP Running Management (phpRunMan) before 1.0.3 allows remote attackers to inject arbitrary web script or HTML via the message parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0259">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:minimal_design:minimal_gallery:0.8" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:minimal_design:minimal_gallery:0.8</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0259</vuln:cve-id>
        <vuln:published-datetime>2008-01-15T15:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:36.483-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>6.4</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-15T15:45:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-22" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27265">27265</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/4902">4902</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28391">28391</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39649">minimalgallery-mgthumbs-file-include(39649)</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple directory traversal vulnerabilities in _mg/php/mg_thumbs.php in minimal Gallery 0.8 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) thumbcat and (2) thumb parameters.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0260">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:minimal_design:minimal_gallery:0.8" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:minimal_design:minimal_gallery:0.8</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0260</vuln:cve-id>
        <vuln:published-datetime>2008-01-15T15:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:36.623-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-15T15:47:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-20" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/4902">4902</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28391">28391</vuln:reference>
        </vuln:references>
        <vuln:summary>minimal Gallery 0.8 allows remote attackers to obtain configuration information via a direct request to php_info.php, which calls the phpinfo function.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0261">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:mambo:mambo_open_source" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:mambo:mambo_open_source</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0261</vuln:cve-id>
        <vuln:published-datetime>2008-01-15T15:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:36.777-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-15T16:02:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-399" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27239">27239</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28392">28392</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://forum.mambo-foundation.org/showthread.php?t=9651">http://forum.mambo-foundation.org/showthread.php?t=9651</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39613">mambo-search-dos(39613)</vuln:reference>
        </vuln:references>
        <vuln:summary>Unspecified vulnerability in the search component and module in Mambo 4.5.x and 4.6.x allows remote attackers to cause a denial of service (query flood) via unspecified vectors.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0262">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:agares_media:phpautovideo:2.21" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:agares_media:phpautovideo:2.21</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0262</vuln:cve-id>
        <vuln:published-datetime>2008-01-15T15:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:36.920-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-15T16:07:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-89" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39641">agares-articleblock-sql-injection(39641)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27258">27258</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/4905">4905</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/4898">4898</vuln:reference>
        </vuln:references>
        <vuln:summary>SQL injection vulnerability in includes/articleblock.php in Agares PhpAutoVideo 2.21 allows remote attackers to execute arbitrary SQL commands via the articlecat parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0263">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:ingate:firewall:4.6" />
                <cpe-lang:fact-ref name="cpe:/a:ingate:ingate_siparator:4.6" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:ingate:ingate_siparator:4.6</vuln:product>
            <vuln:product>cpe:/a:ingate:firewall:4.6</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0263</vuln:cve-id>
        <vuln:published-datetime>2008-01-15T15:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-11-15T02:07:02.157-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-15T16:16:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-399" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1019177">1019177</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1019176">1019176</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27222">27222</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ingate.com/relnote-461.php">http://www.ingate.com/relnote-461.php</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/0108">ADV-2008-0108</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28394">28394</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://osvdb.org/40365">40365</vuln:reference>
        </vuln:references>
        <vuln:summary>The SIP module in Ingate Firewall before 4.6.1 and SIParator before 4.6.1 does not reuse SIP media ports in unspecified call hold and send-only stream scenarios, which allows remote attackers to cause a denial of service (port exhaustion) via unspecified vectors.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0264">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:drupal:meta_tags_module:5.x-1.6" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:drupal:meta_tags_module:5.x-1.6</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0264</vuln:cve-id>
        <vuln:published-datetime>2008-01-15T15:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:37.217-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>6.8</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-15T16:28:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-20" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://drupal.org/node/209759">http://drupal.org/node/209759</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/0129">ADV-2008-0129</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28478">28478</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39638">drupal-metatags-code-execution(39638)</vuln:reference>
        </vuln:references>
        <vuln:summary>Unspecified vulnerability in the Meta Tags (aka Nodewords) 5.x-1.6 module for Drupal, when images are permitted in node bodies, allows remote authenticated users to execute arbitrary code via unspecified vectors involving creation of a node.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0265">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:f5:big-ip:9.4.3" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:f5:big-ip:9.4.3</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0265</vuln:cve-id>
        <vuln:published-datetime>2008-01-15T15:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:37.373-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-15T16:35:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-79" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39632">f5bigip-searchstring-xss(39632)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1019190">1019190</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27272">27272</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/486217/100/0/threaded">20080114 F5 BIG-IP Web Management List Search XSS</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/0181">ADV-2008-0181</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28505">28505</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/3545">3545</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in the Search function in the web management interface in F5 BIG-IP 9.4.3 allow remote attackers to inject arbitrary web script or HTML via the SearchString parameter to (1) list_system.jsp, (2) list_pktfilter.jsp, (3) list_ltm.jsp, (4) resources_audit.jsp, and (5) list_asm.jsp in tmui/Control/jspmap/tmui/system/log/; and (6) list.jsp in certain directories.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0266">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:eticket:eticket:1.5.5.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:eticket:eticket:1.5.5.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0266</vuln:cve-id>
        <vuln:published-datetime>2008-01-15T15:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:37.527-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>2.6</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>HIGH</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-16T08:38:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-352" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39490">eticket-admin-csrf(39490)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27173">27173</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/485835/100/0/threaded">20080106 eTicket 1.5.5.2 Multiple Vulnerabilities</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28331">28331</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/3542">3542</vuln:reference>
        </vuln:references>
        <vuln:summary>Cross-site request forgery (CSRF) vulnerability in admin.php in eTicket 1.5.5.2 allows remote attackers to change the administrative password and possibly perform other administrative tasks.  NOTE: either the old password must be known, or the attacker must leverage a separate SQL injection vulnerability.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0267">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:eticket:eticket:1.5.5.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:eticket:eticket:1.5.5.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0267</vuln:cve-id>
        <vuln:published-datetime>2008-01-15T15:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-09-15T01:10:47.187-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-16T08:40:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-89" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39489">eticket-search-sql-injection(39489)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39487">eticket-admin-sql-injection(39487)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27173">27173</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/485835/100/0/threaded">20080106 eTicket 1.5.5.2 Multiple Vulnerabilities</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28331">28331</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/3542">3542</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple SQL injection vulnerabilities in eTicket 1.5.5.2 allow remote authenticated users to execute arbitrary SQL commands via the (1) status, (2) sort, and (3) way parameters to search.php; and allow remote authenticated administrators to execute arbitrary SQL commands via the (4) msg and (5) password parameters to admin.php.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0268">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:eticket:eticket:1.5.5.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:eticket:eticket:1.5.5.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0268</vuln:cve-id>
        <vuln:published-datetime>2008-01-15T15:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:37.827-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>5.8</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-16T08:40:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-79" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39488">eticket-view-xss(39488)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27173">27173</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/485835/100/0/threaded">20080106 eTicket 1.5.5.2 Multiple Vulnerabilities</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28331">28331</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/3542">3542</vuln:reference>
        </vuln:references>
        <vuln:summary>Cross-site scripting (XSS) vulnerability in view.php in eTicket 1.5.5.2 allows remote attackers to inject arbitrary web script or HTML via the s parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0269">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:10" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:sun:solaris:10</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0269</vuln:cve-id>
        <vuln:published-datetime>2008-01-15T15:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:37.967-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>4.9</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-16T08:44:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:5400" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5400" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-103188-1">103188</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39631">solaris-dotoprocs-dos(39631)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1019186">1019186</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27260">27260</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/0130">ADV-2008-0130</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-66-201513-1">201513</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28491">28491</vuln:reference>
        </vuln:references>
        <vuln:summary>Unspecified vulnerability in the dotoprocs function in Sun Solaris 10 allows local users to cause a denial of service (panic) via unspecified vectors.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0270">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:taskfreak:taskfreak:0.6.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:taskfreak:taskfreak:0.6.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0270</vuln:cve-id>
        <vuln:published-datetime>2008-01-15T15:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:38.123-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>6.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-16T08:46:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-89" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/4899">4899</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39645">taskfreak-index-sql-injection(39645)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27257">27257</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28448">28448</vuln:reference>
        </vuln:references>
        <vuln:summary>SQL injection vulnerability in index.php in TaskFreak! 0.6.1 and earlier allows remote authenticated users to execute arbitrary SQL commands via the sContext parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0271">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:drupal:bueditor:4.7.x-1.0" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:bueditor:5.x-1.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:drupal:bueditor:5.x-1.0</vuln:product>
            <vuln:product>cpe:/a:drupal:bueditor:4.7.x-1.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0271</vuln:cve-id>
        <vuln:published-datetime>2008-01-15T15:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:38.263-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-16T10:45:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-352" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28418">28418</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://drupal.org/node/208534">http://drupal.org/node/208534</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39614">drupal-bueditor-csrf(39614)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/0128">ADV-2008-0128</vuln:reference>
        </vuln:references>
        <vuln:summary>The editor deletion form in BUEditor 4.7.x before 4.7.x-1.0 and 5.x before 5.x-1.1, a module for Drupal, does not follow Drupal's Forms API submission model, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and delete custom editor interfaces.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0272">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.0.0" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.1.0" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.2.0_rc" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.4" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.4.1" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.4.2" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.4.3" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.5" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.5.1" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.5.2" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.5.3" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.5.4" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.5.5" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.5.6" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.5.7" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.5.8" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.1" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.10" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.11" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.2" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.3" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.4" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.5" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.6" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.7" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.8" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.9" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7.1" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7.10" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7.2" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7.3" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7.4" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7.5" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7.6" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7.7" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7.8" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7.9" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7_rev_1.15" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7_rev_1.2" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:5.0" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:5.1" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:5.1_rev1.1" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:5.2" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:5.3" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:5.4" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:5.5." />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:drupal:drupal:4.7.2</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.6.7</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.6</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.7.1</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.7</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.6.6</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.4</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.6.5</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.5</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.6.4</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.6.9</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.6.8</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.7_rev_1.2</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.7.9</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.7.8</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.7.7</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.7.6</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.6.3</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.7.5</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.1.0</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.6.2</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.7.4</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.6.1</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:5.5.</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.7.3</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.7_rev_1.15</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.2.0_rc</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:5.2</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:5.1</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:5.0</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.0.0</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.4.1</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.4.3</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.5.6</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.5.5</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.4.2</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:5.3</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.5.8</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.6.11</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:5.4</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.5.7</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.5.2</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.5.1</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.6.10</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:5.1_rev1.1</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.5.4</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.5.3</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.7.10</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0272</vuln:cve-id>
        <vuln:published-datetime>2008-01-15T15:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-09-15T01:10:47.670-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-16T10:35:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-352" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27238">27238</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39617">drupal-aggregator-csrf(39617)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vupen.com/english/advisories/2008/0134">ADV-2008-0134</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vbdrupal.org/forum/showthread.php?t=1349">http://www.vbdrupal.org/forum/showthread.php?t=1349</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vbdrupal.org/forum/showthread.php?p=6878">http://www.vbdrupal.org/forum/showthread.php?p=6878</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28486">28486</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28422">28422</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://drupal.org/node/208562">http://drupal.org/node/208562</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/0127">ADV-2008-0127</vuln:reference>
        </vuln:references>
        <vuln:summary>Cross-site request forgery (CSRF) vulnerability in the aggregator module in Drupal 4.7.x before 4.7.11 and 5.x before 5.6 allows remote attackers to delete items from a feed as privileged users.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0273">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.0.0" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.1.0" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.2.0_rc" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.4" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.4.1" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.4.2" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.4.3" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.5" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.5.1" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.5.2" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.5.3" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.5.4" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.5.5" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.5.6" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.5.7" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.5.8" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.1" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.10" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.11" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.2" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.3" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.4" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.5" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.6" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.7" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.8" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.9" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7.1" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7.10" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7.2" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7.3" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7.4" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7.5" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7.6" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7.7" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7.8" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7.9" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7_rev_1.15" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7_rev_1.2" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:5.0" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:5.1" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:5.1_rev1.1" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:5.2" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:5.3" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:5.4" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:5.5." />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:drupal:drupal:4.7.2</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.6.7</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.6</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.7.1</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.7</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.6.6</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.4</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.6.5</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.5</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.6.4</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.6.9</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.6.8</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.7_rev_1.2</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.7.9</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.7.8</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.7.7</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.7.6</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.6.3</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.7.5</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.1.0</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.6.2</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.7.4</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.6.1</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:5.5.</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.7.3</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.7_rev_1.15</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.2.0_rc</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:5.2</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:5.1</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:5.0</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.0.0</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.4.1</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.4.3</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.5.6</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.5.5</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.4.2</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:5.3</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.5.8</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.6.11</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:5.4</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.5.7</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.5.2</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.5.1</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.6.10</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:5.1_rev1.1</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.5.4</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.5.3</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.7.10</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0273</vuln:cve-id>
        <vuln:published-datetime>2008-01-15T15:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-09-15T01:10:47.797-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-16T10:55:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-79" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27238">27238</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28422">28422</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39619">drupal-utf8-xss(39619)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vupen.com/english/advisories/2008/0134">ADV-2008-0134</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vbdrupal.org/forum/showthread.php?t=1349">http://www.vbdrupal.org/forum/showthread.php?t=1349</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vbdrupal.org/forum/showthread.php?p=6878">http://www.vbdrupal.org/forum/showthread.php?p=6878</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28486">28486</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://drupal.org/node/208564">http://drupal.org/node/208564</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/0127">ADV-2008-0127</vuln:reference>
        </vuln:references>
        <vuln:summary>Interpretation conflict in Drupal 4.7.x before 4.7.11 and 5.x before 5.6, when Internet Explorer 6 is used, allows remote attackers to conduct cross-site scripting (XSS) attacks via invalid UTF-8 byte sequences, which are not processed as UTF-8 by Drupal's HTML filtering, but are processed as UTF-8 by Internet Explorer, effectively removing characters from the document and defeating the HTML protection mechanism.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0274">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:5.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:drupal:drupal:4.7</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:5.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0274</vuln:cve-id>
        <vuln:published-datetime>2008-01-15T15:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-09-15T01:10:47.937-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>2.6</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>HIGH</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-16T11:02:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-79" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27238">27238</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28422">28422</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39605">drupal-theme-xss(39605)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vupen.com/english/advisories/2008/0134">ADV-2008-0134</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vbdrupal.org/forum/showthread.php?t=1349">http://www.vbdrupal.org/forum/showthread.php?t=1349</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vbdrupal.org/forum/showthread.php?p=6878">http://www.vbdrupal.org/forum/showthread.php?p=6878</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28486">28486</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://drupal.org/node/208565">http://drupal.org/node/208565</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/0127">ADV-2008-0127</vuln:reference>
        </vuln:references>
        <vuln:summary>Cross-site scripting (XSS) vulnerability in Drupal 4.7.x and 5.x, when certain .htaccess protections are disabled, allows remote attackers to inject arbitrary web script or HTML via crafted links involving theme .tpl.php files.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0275">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:drupal:atom_module:4.7" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:atom_module:5.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:drupal:atom_module:5.0</vuln:product>
            <vuln:product>cpe:/a:drupal:atom_module:4.7</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0275</vuln:cve-id>
        <vuln:published-datetime>2008-01-15T15:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:39.107-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-16T11:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-264" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39607">drupal-atom-security-bypass(39607)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://drupal.org/node/208527">http://drupal.org/node/208527</vuln:reference>
        </vuln:references>
        <vuln:summary>The Atom 4.7 before 4.7.x-1.0 and 5.x before 5.x-1.0 module for Drupal does not properly manage permissions for node (1) titles, (2) teasers, and (3) bodies, which might allow remote attackers to gain access to syndicated content.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0276">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.0.0" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.1.0" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.2.0_rc" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.4" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.4.1" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.4.2" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.4.3" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.5" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.5.1" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.5.2" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.5.3" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.5.4" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.5.5" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.5.6" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.5.7" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.5.8" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.1" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.10" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.11" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.2" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.3" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.4" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.5" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.6" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.7" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.8" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.9" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7.1" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7.10" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7.2" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7.3" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7.4" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7.5" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7.6" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7.7" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7.8" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7.9" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7_rev_1.15" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7_rev_1.2" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:5.0" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:5.1" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:5.1_rev1.1" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:5.2" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:5.3" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:5.4" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:5.5." />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:drupal:drupal:4.7.2</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.6.7</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.6</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.7.1</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.7</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.6.6</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.4</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.6.5</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.5</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.6.4</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.6.9</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.6.8</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.7_rev_1.2</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.7.9</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.7.8</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.7.7</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.7.6</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.6.3</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.7.5</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.1.0</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.6.2</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.7.4</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.6.1</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:5.5.</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.7.3</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.7_rev_1.15</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.2.0_rc</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:5.2</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:5.1</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:5.0</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.0.0</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.4.1</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.4.3</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.5.6</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.5.5</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.4.2</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:5.3</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.5.8</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.6.11</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:5.4</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.5.7</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.5.2</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.5.1</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.6.10</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:5.1_rev1.1</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.5.4</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.5.3</vuln:product>
            <vuln:product>cpe:/a:drupal:drupal:4.7.10</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0276</vuln:cve-id>
        <vuln:published-datetime>2008-01-15T15:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:39.277-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-16T11:04:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-79" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39606">drupal-devel-variable-xss(39606)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://drupal.org/node/208524">http://drupal.org/node/208524</vuln:reference>
        </vuln:references>
        <vuln:summary>Cross-site scripting (XSS) vulnerability in the Devel module before 5.x-0.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via a site variable, related to lack of escaping of the variable table.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0277">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:drupal:fileshare_module:4.7.x" />
                <cpe-lang:fact-ref name="cpe:/a:drupal:fileshare_module:5.x" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:drupal:fileshare_module:4.7.x</vuln:product>
            <vuln:product>cpe:/a:drupal:fileshare_module:5.x</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0277</vuln:cve-id>
        <vuln:published-datetime>2008-01-15T15:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:39.543-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>8.5</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-16T11:06:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:cwe id="CWE-20" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39609">drupal-fileshare-code-execution(39609)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://drupal.org/node/208537">http://drupal.org/node/208537</vuln:reference>
        </vuln:references>
        <vuln:summary>Unspecified vulnerability in the Fileshare module for Drupal allows remote authenticated users with node-creation privileges to execute arbitrary code via unspecified vectors.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0278">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:x7_group:x7_chat:2.0.5" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:x7_group:x7_chat:2.0.5</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0278</vuln:cve-id>
        <vuln:published-datetime>2008-01-15T15:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:39.700-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>6.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-16T11:07:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:cwe id="CWE-89" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39656">x7chatday-sql-injection(39656)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27277">27277</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/4907">4907</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28503">28503</vuln:reference>
        </vuln:references>
        <vuln:summary>SQL injection vulnerability in index.php in X7 Chat 2.0.5 and possibly earlier allows remote attackers to execute arbitrary SQL commands via the day parameter in a sm_window action.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0279">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:xforum:xforum:1.4" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:xforum:xforum:1.4</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0279</vuln:cve-id>
        <vuln:published-datetime>2008-01-15T15:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:39.840-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-16T11:10:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:cwe id="CWE-89" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39654">xforum-liretopic-sql-injection(39654)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27278">27278</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/4908">4908</vuln:reference>
        </vuln:references>
        <vuln:summary>SQL injection vulnerability in liretopic.php in Xforum 1.4 and possibly others allows remote attackers to execute arbitrary SQL commands via the topic parameter.  NOTE: the categorie parameter might also be affected.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0173">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:gforge:gforge:4.6.99" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:gforge:gforge:4.6.99</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0173</vuln:cve-id>
        <vuln:published-datetime>2008-01-15T15:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2008-09-05T17:34:23.640-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.5</cvss:score>
            