257411
|
- |
|
phpeasynews
|
phpeasyblog
|
SQL injection vulnerability in newsarchive.php in PHPeasyblog (formerly phpeasynews) 1.13 RC2 and earlier allows remote attackers to execute arbitrary SQL commands via the post parameter.
|
CWE-89
SQL Injection
|
CVE-2008-2823
|
2017-09-29 10:31 |
2008-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257412
|
- |
|
fullrevolution
|
aspwebcalendar2008
|
Unrestricted file upload vulnerability in calendar_admin.asp in Full Revolution aspWebCalendar 2008 allows remote attackers to upload and execute arbitrary code via the FILE1 parameter in an uploadfi…
|
CWE-94
Code Injection
|
CVE-2008-2832
|
2017-09-29 10:31 |
2008-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257413
|
- |
|
worldlevel
|
le.cms
|
admin/upload.php in le.cms 1.4 and earlier allows remote attackers to bypass administrative authentication, and upload and execute arbitrary files in images/, via a nonzero value for the submit0 para…
|
CWE-287
Improper Authentication
|
CVE-2008-2833
|
2017-09-29 10:31 |
2008-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257414
|
- |
|
sidb
|
scientific_image_database
|
SQL injection vulnerability in projects.php in Scientific Image DataBase 0.41 allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2008-2834
|
2017-09-29 10:31 |
2008-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257415
|
- |
|
igsuite
|
igsuite
|
SQL injection vulnerability in cgi-bin/igsuite in IGSuite 3.2.4 allows remote attackers to execute arbitrary SQL commands via the formid parameter.
|
CWE-89
SQL Injection
|
CVE-2008-2835
|
2017-09-29 10:31 |
2008-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257416
|
- |
|
k5n
|
webcalendar
|
PHP remote file inclusion vulnerability in send_reminders.php in WebCalendar 1.0.4 allows remote attackers to execute arbitrary PHP code via a URL in the includedir parameter and a 0 value for the no…
|
CWE-94
Code Injection
|
CVE-2008-2836
|
2017-09-29 10:31 |
2008-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257417
|
- |
|
cms.brdconcept
|
cms-brd
|
SQL injection vulnerability in index.php in CMS-BRD allows remote attackers to execute arbitrary SQL commands via the menuclick parameter.
|
CWE-89
SQL Injection
|
CVE-2008-2837
|
2017-09-29 10:31 |
2008-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257418
|
- |
|
traindepot
|
traindepot
|
Directory traversal vulnerability in index.php in Traindepot 0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the module parameter.
|
CWE-22
Path Traversal
|
CVE-2008-2838
|
2017-09-29 10:31 |
2008-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257419
|
- |
|
traindepot
|
traindepot
|
Cross-site scripting (XSS) vulnerability in the search module in Traindepot 0.1 allows remote attackers to inject arbitrary web script or HTML via the query parameter to index.php.
|
CWE-79
Cross-site Scripting
|
CVE-2008-2839
|
2017-09-29 10:31 |
2008-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257420
|
- |
|
doitlive
|
cms
|
Cross-site scripting (XSS) vulnerability in edit/showmedia.asp in doITLive CMS 2.50 and earlier allows remote attackers to inject arbitrary web script or HTML via the FILE parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2008-2842
|
2017-09-29 10:31 |
2008-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|