256821
|
- |
|
buzzscripts
|
buzzywall
|
Directory traversal vulnerability in download.php in BuzzyWall 1.3.1 allows remote attackers to read arbitrary local files via a .. (dot dot) in the id parameter.
|
CWE-22
Path Traversal
|
CVE-2008-4759
|
2017-09-29 10:32 |
2008-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256822
|
- |
|
graphiks
|
myforum
|
SQL injection vulnerability in lecture.php in Graphiks MyForum 1.3, when register_globals is enabled, allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2008-4760
|
2017-09-29 10:32 |
2008-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256823
|
- |
|
extplorer
|
com_extplorer
|
Directory traversal vulnerability in the eXtplorer module (com_extplorer) 2.0.0 RC2 and earlier in Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the dir parameter in a…
|
CWE-22
Path Traversal
|
CVE-2008-4764
|
2017-09-29 10:32 |
2008-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256824
|
- |
|
oscommerce
|
poll_booth
|
SQL injection vulnerability in pollBooth.php in osCommerce Poll Booth Add-On 2.0 allows remote attackers to execute arbitrary SQL commands via the pollID parameter in a results operation. NOTE: this…
|
CWE-89
SQL Injection
|
CVE-2008-4765
|
2017-09-29 10:32 |
2008-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256825
|
- |
|
realvnc
|
realvnc
|
The CMsgReader::readRect function in the VNC Viewer component in RealVNC VNC Free Edition 4.0 through 4.1.2, Enterprise Edition E4.0 through E4.4.2, and Personal Edition P4.0 through P4.4.2 allows re…
|
CWE-20
Improper Input Validation
|
CVE-2008-4770
|
2017-09-29 10:32 |
2009-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256826
|
- |
|
4xem d-link vivotek
|
vatctrl_class mpeg4_shm_audio_control rtsp_mpeg4_sp_control
|
Stack-based buffer overflow in VATDecoder.VatCtrl.1 ActiveX control in (1) 4xem VatCtrl Class (VATDecoder.dll 1.0.0.27 and 1.0.0.51), (2) D-Link MPEG4 SHM Audio Control (VAPGDecoder.dll 1.7.0.5), (3)…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2008-4771
|
2017-09-29 10:32 |
2008-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256827
|
- |
|
questwork
|
questcms
|
SQL injection vulnerability in main/main.php in QuestCMS allows remote attackers to execute arbitrary SQL commands via the obj parameter.
|
CWE-89
SQL Injection
|
CVE-2008-4772
|
2017-09-29 10:32 |
2008-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256828
|
- |
|
questwork
|
questcms
|
Directory traversal vulnerability in main/main.php in QuestCMS allows remote attackers to read arbitrary local files via a .. (dot dot) in the theme parameter.
|
CWE-22
Path Traversal
|
CVE-2008-4773
|
2017-09-29 10:32 |
2008-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256829
|
- |
|
questwork
|
questcms
|
Cross-site scripting (XSS) vulnerability in main/main.php in QuestCMS allows remote attackers to inject arbitrary web script or HTML via the cx parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2008-4774
|
2017-09-29 10:32 |
2008-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256830
|
- |
|
tguzip
|
tguzip
|
Stack-based buffer overflow in TUGzip 3.5.0.0 allows remote attackers to denial of service (crash) or execute arbitrary code via a long filename in a .zip file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2008-4779
|
2017-09-29 10:32 |
2008-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|