258691
|
- |
|
2wire
|
1701hg 1800hw 2071hg 2700hg
|
Cross-site request forgery (CSRF) vulnerability in the xslt script in the web-based management interface on the 2wire 1701HG, 1800HW, 2071HG, and 2700HG with firmware 3.17.5, 3.7.1, 4.25.19, or 5.29.…
|
CWE-352
Origin Validation Error
|
CVE-2008-6605
|
2017-09-29 10:33 |
2009-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258692
|
- |
|
matpo
|
matpo_link
|
SQL injection vulnerability in view.php in MatPo Link 1.2 Beta allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2008-6606
|
2017-09-29 10:33 |
2009-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258693
|
- |
|
matpo
|
matpo_link
|
Cross-site scripting (XSS) vulnerability in view.php in MatPo Link 1.2 Beta allows remote attackers to inject arbitrary web script or HTML via the thema parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2008-6607
|
2017-09-29 10:33 |
2009-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258694
|
- |
|
developiteasy
|
events_calendar
|
Multiple SQL injection vulnerabilities in DevelopItEasy Events Calendar 1.2 allow remote attackers to execute arbitrary SQL commands via (1) the user_name parameter (aka user field) to admin/index.ph…
|
CWE-89
SQL Injection
|
CVE-2008-6608
|
2017-09-29 10:33 |
2009-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258695
|
- |
|
abweb
|
minimal_ablog
|
SQL injection vulnerability in index.php in Minimal ABlog 0.4 allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2008-6611
|
2017-09-29 10:33 |
2009-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258696
|
- |
|
abweb
|
minimal-ablog
|
Unrestricted file upload vulnerability in admin/uploader.php in Minimal ABlog 0.4 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it…
|
CWE-94
Code Injection
|
CVE-2008-6612
|
2017-09-29 10:33 |
2009-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258697
|
- |
|
abweb
|
minimal-ablog
|
uploader.php in minimal-ablog 0.4 does not properly restrict access, which allows remote attackers to gain administrative privileges via a direct request.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-6613
|
2017-09-29 10:33 |
2009-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258698
|
- |
|
impliedbydesign
|
ibd_micro_cms
|
Multiple SQL injection vulnerabilities in microcms-admin-login.php in Implied By Design (IBD) Micro CMS 3.5 (aka 0.3.5) allow remote attackers to execute arbitrary SQL commands via (1) the administra…
|
CWE-89
SQL Injection
|
CVE-2008-6614
|
2017-09-29 10:33 |
2009-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258699
|
- |
|
webbdomian
|
post_card
|
SQL injection vulnerability in choosecard.php in WEBBDOMAIN Post Card (aka Web Postcards) 1.02, 1.01, and earlier allows remote attackers to execute arbitrary SQL commands via the catid parameter.
|
CWE-89
SQL Injection
|
CVE-2008-6622
|
2017-09-29 10:33 |
2009-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258700
|
- |
|
webbdomain
|
post_card
|
SQL injection vulnerability in getin.php in WEBBDOMAIN Post Card (aka Web Postcards) 1.02 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter.
|
CWE-89
SQL Injection
|
CVE-2008-6623
|
2017-09-29 10:33 |
2009-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|