265531
|
- |
|
alphadmin
|
alphadmin_cms
|
AlphAdmin CMS 1.0.5/03 allows remote attackers to bypass authentication and gain administrative access by setting the aa_login cookie value to 1. NOTE: the provenance of this information is unknown;…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-3300
|
2017-08-8 10:31 |
2008-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265532
|
- |
|
youtube_blog
|
youtube_blog
|
SQL injection vulnerability in info.php in C. Desseno YouTube Blog (ytb) 0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2008-3307. NO…
|
CWE-89
SQL Injection
|
CVE-2008-3306
|
2017-08-8 10:31 |
2008-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265533
|
- |
|
lemoncms
|
lemon_cms
|
Directory traversal vulnerability in lemon_includes/FCKeditor/editor/filemanager/browser/browser.php in Lemon CMS 1.10 allows remote attackers to include and execute arbitrary local files via a .. (d…
|
CWE-22
Path Traversal
|
CVE-2008-3312
|
2017-08-8 10:31 |
2008-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265534
|
- |
|
creacms
|
creacms
|
Multiple PHP remote file inclusion vulnerabilities in CreaCMS 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the (1) cfg[document_uri] parameter to _administration/edition_arti…
|
CWE-94
Code Injection
|
CVE-2008-3313
|
2017-08-8 10:31 |
2008-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265535
|
- |
|
portalparts
|
forum_plugin
|
Cross-site scripting (XSS) vulnerability in the search feature in the Forum plugin before 2.7.1 for Geeklog allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, pro…
|
CWE-79
Cross-site Scripting
|
CVE-2008-3316
|
2017-08-8 10:31 |
2008-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265536
|
- |
|
edgewall_software
|
trac
|
Cross-site scripting (XSS) vulnerability in the wiki engine in Trac before 0.10.5 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2008-3328
|
2017-08-8 10:31 |
2008-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265537
|
- |
|
twibright
|
links
|
Unspecified vulnerability in Links before 2.1, when "only proxies" is enabled, has unknown impact and attack vectors related to providing "URLs to external programs."
|
CWE-59 NVD-CWE-noinfo
Link Following
|
CVE-2008-3329
|
2017-08-8 10:31 |
2008-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265538
|
- |
|
debian
|
horde turba
|
Cross-site scripting (XSS) vulnerability in services/obrowser/index.php in Horde 3.2 and Turba 2.2 allows remote attackers to inject arbitrary web script or HTML via the contact name.
|
CWE-79
Cross-site Scripting
|
CVE-2008-3330
|
2017-08-8 10:31 |
2008-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265539
|
- |
|
mantis
|
mantis
|
Directory traversal vulnerability in core/lang_api.php in Mantis before 1.1.2 allows remote attackers to include and execute arbitrary files via the language parameter to the user preferences page (a…
|
CWE-22
Path Traversal
|
CVE-2008-3333
|
2017-08-8 10:31 |
2008-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265540
|
- |
|
mybb
|
mybb
|
Cross-site scripting (XSS) vulnerability in MyBB 1.2.x before 1.2.14 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly involving search.php.
|
CWE-79
Cross-site Scripting
|
CVE-2008-3334
|
2017-08-8 10:31 |
2008-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|