257761
|
- |
|
intellitamper
|
intellitamper
|
Buffer overflow in the HTML parser in IntelliTamper 2.07 allows remote attackers to execute arbitrary code via a long URL in the SRC attribute of an IMG element. NOTE: this might be related to CVE-2…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2008-3583
|
2017-09-29 10:31 |
2008-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257762
|
- |
|
pozscripts
|
greencart_php_shopping_cart
|
Multiple SQL injection vulnerabilities in PozScripts GreenCart PHP Shopping Cart allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) product_desc.php and (2) store_in…
|
CWE-89
SQL Injection
|
CVE-2008-3585
|
2017-09-29 10:31 |
2008-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257763
|
- |
|
joomla
|
com_ezstore
|
SQL injection vulnerability in the EZ Store (com_ezstore) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php.
|
CWE-89
SQL Injection
|
CVE-2008-3586
|
2017-09-29 10:31 |
2008-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257764
|
- |
|
phsblog
|
phsblog
|
Multiple SQL injection vulnerabilities in phsBlog 0.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) eid parameter to comments.php, (2) cid parameter to index.php, and the (3)…
|
CWE-89
SQL Injection
|
CVE-2008-3588
|
2017-09-29 10:31 |
2008-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257765
|
- |
|
mozilo
|
mozilocms
|
Directory traversal vulnerability in download.php in moziloCMS 1.10.1, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the cat parameter.
|
CWE-22
Path Traversal
|
CVE-2008-3589
|
2017-09-29 10:31 |
2008-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257766
|
- |
|
21degrees
|
symphony
|
SQL injection vulnerability in lib/class.admin.php in Twentyone Degrees Symphony 1.7.01 and earlier allows remote attackers to execute arbitrary SQL commands via the sym_auth cookie in a /publish/fil…
|
CWE-89
SQL Injection
|
CVE-2008-3591
|
2017-09-29 10:31 |
2008-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257767
|
- |
|
21degrees
|
symphony
|
Unrestricted file upload vulnerability in the File Manager in the admin panel in Twentyone Degrees Symphony 1.7.01 and earlier allows remote attackers to execute arbitrary code by uploading a file wi…
|
CWE-94
Code Injection
|
CVE-2008-3592
|
2017-09-29 10:31 |
2008-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257768
|
- |
|
21degrees
|
symphony
|
Successful exploitation of this vulnerability requires valid administrator credentials. See CVE-2008-3591 for more information.
|
CWE-94
Code Injection
|
CVE-2008-3592
|
2017-09-29 10:31 |
2008-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257769
|
- |
|
syzygycms
|
syzygycms
|
Directory traversal vulnerability in index.php in SyzygyCMS 0.3 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter.
|
CWE-22
Path Traversal
|
CVE-2008-3593
|
2017-09-29 10:31 |
2008-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257770
|
- |
|
magicscripts
|
e-store_kit-1 e-store_kit-2
|
SQL injection vulnerability in viewdetails.php in MagicScripts E-Store Kit-1, E-Store Kit-2, E-Store Kit-1 Pro PayPal Edition, and E-Store Kit-2 PayPal Edition allows remote attackers to execute arbi…
|
CWE-89
SQL Injection
|
CVE-2008-3594
|
2017-09-29 10:31 |
2008-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|