258741
|
- |
|
bluocms
|
bluo_cms
|
SQL injection vulnerability in index.php in Bluo CMS 1.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2008-6281
|
2017-09-29 10:33 |
2009-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258742
|
- |
|
ortus.nirn
|
cms_ortus
|
SQL injection vulnerability in engine/users/users_edit_pub.inc in CMS Ortus 1.13 and earlier allows remote authenticated users to execute arbitrary SQL commands via the city parameter in a users_edit…
|
CWE-89
SQL Injection
|
CVE-2008-6282
|
2017-09-29 10:33 |
2009-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258743
|
- |
|
1scripts
|
z1exchange
|
SQL injection vulnerability in edit.php in Z1Exchange 1.0 allows remote attackers to execute arbitrary SQL commands via the site parameter.
|
CWE-89
SQL Injection
|
CVE-2008-6284
|
2017-09-29 10:33 |
2009-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258744
|
- |
|
businessvein
|
php_tv_portal
|
SQL injection vulnerability in index.php in PHP TV Portal 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the mid parameter.
|
CWE-89
SQL Injection
|
CVE-2008-6285
|
2017-09-29 10:33 |
2009-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258745
|
- |
|
activewebsoftwares
|
active_newsletter
|
Multiple SQL injection vulnerabilities in SubscriberStart.asp in Active Newsletter 4.3 allow remote attackers to execute arbitrary SQL commands via (1) the email parameter (aka username or E-mail fie…
|
CWE-89
SQL Injection
|
CVE-2008-6286
|
2017-09-29 10:33 |
2009-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258746
|
- |
|
getmiro
|
broadcast_machine
|
Multiple PHP remote file inclusion vulnerabilities in Broadcast Machine 0.1 allow remote attackers to execute arbitrary PHP code via a URL in the baseDir parameter to (1) MySQLController.php, (2) SQL…
|
CWE-94
Code Injection
|
CVE-2008-6287
|
2017-09-29 10:33 |
2009-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258747
|
- |
|
interface-medien
|
ibase
|
Directory traversal vulnerability in download.php in Interface Medien ibase 2.03 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter.
|
CWE-22
Path Traversal
|
CVE-2008-6288
|
2017-09-29 10:33 |
2009-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258748
|
- |
|
toursmanager
|
tours_manager
|
SQL injection vulnerability in cityview.php in Tours Manager 1.0 allows remote attackers to execute arbitrary SQL commands via the cityid parameter.
|
CWE-89
SQL Injection
|
CVE-2008-6289
|
2017-09-29 10:33 |
2009-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258749
|
- |
|
niclor
|
include_sito
|
Directory traversal vulnerability in includefile.php in nicLOR Sito, when register_globals is enabled or magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary files v…
|
CWE-22
Path Traversal
|
CVE-2008-6290
|
2017-09-29 10:33 |
2009-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258750
|
- |
|
accscripts
|
acc_php_email
|
Acc PHP eMail 1.1 allows remote attackers to bypass authentication and gain administrative access by setting the NEWSLETTERLOGIN cookie to "admin".
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-6291
|
2017-09-29 10:33 |
2009-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|