260311
|
- |
|
sylvain_pasquet
|
bbzl_php
|
Directory traversal vulnerability in index.php in BbZL.PhP 0.92 allows remote attackers to access unauthorized directories via a .. (dot dot) in the lien_2 parameter.
|
CWE-22
Path Traversal
|
CVE-2008-4707
|
2017-09-29 10:32 |
2008-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260312
|
- |
|
sylvain_pasquet
|
bbzl.php
|
BbZL.PhP 0.92 allows remote attackers to bypass authentication and gain administrative access by setting the phorum_admin_session cookie to 1.
|
CWE-287
Improper Authentication
|
CVE-2008-4708
|
2017-09-29 10:32 |
2008-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260313
|
- |
|
pilot_group
|
etraining
|
SQL injection vulnerability in news_read.php in Pilot Group (PG) eTraining allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2008-4709
|
2017-09-29 10:32 |
2008-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260314
|
- |
|
joovili
|
joovili
|
SQL injection vulnerability in Joovili 3.0 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter to (1) view.blog.php, (2) vie…
|
CWE-89
SQL Injection
|
CVE-2008-4711
|
2017-09-29 10:32 |
2008-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260315
|
- |
|
lnblog
|
lnblog
|
Directory traversal vulnerability in pages/showblog.php in LnBlog 0.9.0 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (…
|
CWE-22
Path Traversal
|
CVE-2008-4712
|
2017-09-29 10:32 |
2008-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260316
|
- |
|
212cafe
|
212cafeboard
|
SQL injection vulnerability in view.php in 212cafe Board 0.07 allows remote attackers to execute arbitrary SQL commands via the qID parameter.
|
CWE-89
SQL Injection
|
CVE-2008-4713
|
2017-09-29 10:32 |
2008-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260317
|
- |
|
atomic_photo_album
|
atomic_photo_album
|
Atomic Photo Album 1.1.0 pre4 does not properly handle the apa_cookie_login and apa_cookie_password cookies, which probably allows remote attackers to bypass authentication and gain administrative ac…
|
CWE-287
Improper Authentication
|
CVE-2008-4714
|
2017-09-29 10:32 |
2008-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260318
|
- |
|
scriptdemo
|
php-lance
|
SQL injection vulnerability in show.php in BitmixSoft PHP-Lance 1.52 allows remote attackers to execute arbitrary SQL commands via the catid parameter.
|
CWE-89
SQL Injection
|
CVE-2008-4716
|
2017-09-29 10:32 |
2008-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260319
|
- |
|
zeeways
|
zeelyrics
|
SQL injection vulnerability in bannerclick.php in ZEELYRICS 2.0 allows remote attackers to execute arbitrary SQL commands via the adid parameter.
|
CWE-89
SQL Injection
|
CVE-2008-4717
|
2017-09-29 10:32 |
2008-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260320
|
- |
|
x7_group
|
x7_chat
|
Directory traversal vulnerability in help/mini.php in X7 Chat 2.0.1 A1 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the help_f…
|
CWE-22
Path Traversal
|
CVE-2008-4718
|
2017-09-29 10:32 |
2008-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|