258141
|
- |
|
miniportail
|
miniportail
|
Directory traversal vulnerability in search.php in miniPortail 2.2 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lng parameter.
|
CWE-22
Path Traversal
|
CVE-2008-6167
|
2017-09-29 10:33 |
2009-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258142
|
- |
|
miniportail
|
miniportail
|
Cross-site scripting (XSS) vulnerability in search.php in miniPortail 2.2 and earlier allows remote attackers to inject arbitrary web script or HTML via an unspecified argument, probably the search s…
|
CWE-79
Cross-site Scripting
|
CVE-2008-6168
|
2017-09-29 10:33 |
2009-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258143
|
- |
|
weberr
|
rwcards
|
Directory traversal vulnerability in captcha/captcha_image.php in the RWCards (com_rwcards) 3.0.11 component for Joomla!, when magic_quotes_gpc is disabled, allows remote attackers to include and exe…
|
CWE-22
Path Traversal
|
CVE-2008-6172
|
2017-09-29 10:33 |
2009-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258144
|
- |
|
k2sxs
|
silvershield
|
SilverSHielD 1.0.2.34 allows remote attackers to cause a denial of service (application crash) via a crafted argument to the opendir SFTP command.
|
CWE-20
Improper Input Validation
|
CVE-2008-6175
|
2017-09-29 10:33 |
2009-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258145
|
- |
|
publicwarehouse
|
lightblog
|
Multiple directory traversal vulnerabilities in LightBlog 9.8, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) use…
|
CWE-22
Path Traversal
|
CVE-2008-6177
|
2017-09-29 10:33 |
2009-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258146
|
- |
|
fckeditor phplist
|
fckeditor phplist
|
Unrestricted file upload vulnerability in editor/filemanager/browser/default/connectors/php/connector.php in FCKeditor 2.2, as used in Falt4 CMS, Nuke ET, and other products, allows remote attackers …
|
CWE-94
Code Injection
|
CVE-2008-6178
|
2017-09-29 10:33 |
2009-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258147
|
- |
|
indexscript
|
indexscript
|
SQL injection vulnerability in sug_cat.php in IndexScript 3.0 allows remote attackers to execute arbitrary SQL commands via the parent_id parameter, a different vector than CVE-2007-4069.
|
CWE-89
SQL Injection
|
CVE-2008-6179
|
2017-09-29 10:33 |
2009-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258148
|
- |
|
mad4media
|
com_mad4joomla
|
SQL injection vulnerability in the Mad4Joomla Mailforms (com_mad4joomla) component before 1.1.8.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the jid parameter to index.…
|
CWE-89
SQL Injection
|
CVE-2008-6181
|
2017-09-29 10:33 |
2009-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258149
|
- |
|
joomla
|
ignitegallery
|
SQL injection vulnerability in the Ignite Gallery (com_ignitegallery) component 0.8.0 through 0.8.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the gallery parameter in …
|
CWE-89
SQL Injection
|
CVE-2008-6182
|
2017-09-29 10:33 |
2009-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258150
|
- |
|
myphpindexer
|
my_php_indexer
|
Multiple directory traversal vulnerabilities in index.php in My PHP Indexer 1.0 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) d and (2) f parameters.
|
CWE-22
Path Traversal
|
CVE-2008-6183
|
2017-09-29 10:33 |
2009-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|