258601
|
- |
|
revou
|
micro_blogging_twitter_clone
|
Multiple SQL injection vulnerabilities in ReVou Micro Blogging Twitter clone allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password fields.
|
CWE-89
SQL Injection
|
CVE-2008-7083
|
2017-09-29 10:33 |
2009-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258602
|
- |
|
thehockeystop
|
hockeystats_online
|
Multiple SQL injection vulnerabilities in TheHockeyStop HockeySTATS Online 2.0 Basic and Advanced allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in the viewpage act…
|
CWE-89
SQL Injection
|
CVE-2008-7085
|
2017-09-29 10:33 |
2009-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258603
|
- |
|
maianscriptworld
|
maian_greetings
|
Maian Greetings 2.1 allows remote attackers to bypass authentication and gain administrative privileges by setting the mecard_admin_cookie cookie to admin.
|
CWE-287
Improper Authentication
|
CVE-2008-7086
|
2017-09-29 10:33 |
2009-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258604
|
- |
|
photopost
|
photopost_vbgallery
|
Unrestricted file upload vulnerability in upload.php in PhotoPost vBGallery 2.4.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension followed…
|
CWE-20
Improper Input Validation
|
CVE-2008-7088
|
2017-09-29 10:33 |
2009-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258605
|
- |
|
qsoft-inc
|
k-rate
|
Multiple SQL injection vulnerabilities in Qsoft K-Rate Premium allow remote attackers to execute arbitrary SQL commands via (1) the $id variable in admin/includes/dele_cpac.php, (2) $ord[order_id] va…
|
CWE-89
SQL Injection
|
CVE-2008-7097
|
2017-09-29 10:33 |
2009-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258606
|
- |
|
qsoft-inc
|
k-rate
|
Multiple cross-site scripting (XSS) vulnerabilities in Qsoft K-Rate Premium allow remote attackers to inject arbitrary web script or HTML via the blog, possibly the (1) Title and (2) Text fields; (3)…
|
CWE-79
Cross-site Scripting
|
CVE-2008-7098
|
2017-09-29 10:33 |
2009-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258607
|
- |
|
qsoft-inc
|
k-rate
|
Unspecified vulnerability in the Manage Templates feature in Qsoft K-Rate Premium allows remote attackers to execute arbitrary PHP code via unknown vectors. NOTE: the provenance of this information …
|
NVD-CWE-noinfo
|
CVE-2008-7099
|
2017-09-29 10:33 |
2009-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258608
|
- |
|
najdi.si
|
toolbar
|
Stack-based buffer overflow in an ActiveX control in najdisitoolbar.dll in Najdi.si Toolbar 2.0.4.1 allows remote attackers to cause a denial of service (browser crash) or execute arbitrary code via …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2008-7103
|
2017-09-29 10:33 |
2009-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258609
|
- |
|
eset
|
smart_security
|
easdrv.sys in ESET Smart Security 3.0.667.0 allows local users to cause a denial of service (crash) via a crafted IOCTL 0x222003 request to the \\.\easdrv device interface.
|
CWE-20
Improper Input Validation
|
CVE-2008-7107
|
2017-09-29 10:33 |
2009-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258610
|
- |
|
ifusionservices
|
ifdate
|
SQL injection vulnerability in members_search.php in iFusion Services iFdate 2.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the name field.
|
CWE-89
SQL Injection
|
CVE-2008-7114
|
2017-09-29 10:33 |
2009-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|