256771
|
- |
|
mywebland
|
mystats
|
SQL injection vulnerability in hits.php in myWebland myStats allows remote attackers to execute arbitrary SQL commands via the sortby parameter.
|
CWE-89
SQL Injection
|
CVE-2008-4643
|
2017-09-29 10:32 |
2008-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256772
|
- |
|
mywebland
|
mystats
|
hits.php in myWebland myStats allows remote attackers to bypass IP address restrictions via a modified X-Forwarded-For HTTP header.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-4644
|
2017-09-29 10:32 |
2008-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256773
|
- |
|
phpwebgallery
|
phpwebgallery
|
plugins/event_tracer/event_list.php in PhpWebGallery 1.7.2 and earlier allows remote authenticated administrators to execute arbitrary PHP code via PHP sequences in the sort parameter, which is proce…
|
CWE-94
Code Injection
|
CVE-2008-4645
|
2017-09-29 10:32 |
2008-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256774
|
- |
|
mywebland
|
myevent
|
SQL injection vulnerability in viewevent.php in myEvent 1.6 allows remote attackers to execute arbitrary SQL commands via the eventdate parameter.
|
CWE-89
SQL Injection
|
CVE-2008-4650
|
2017-09-29 10:32 |
2008-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256775
|
- |
|
dart
|
powertcp_ftp_for_activex
|
Buffer overflow in the ActiveX control (DartFtp.dll) in Dart Communications PowerTCP FTP for ActiveX 2.0.2 0 allows remote attackers to execute arbitrary code via a long SecretKey property.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2008-4652
|
2017-09-29 10:32 |
2008-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256776
|
- |
|
xoops
|
makale
|
SQL injection vulnerability in makale.php in Makale 0.26 and possibly other versions, a module for XOOPS, allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: some o…
|
CWE-89
SQL Injection
|
CVE-2008-4653
|
2017-09-29 10:32 |
2008-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256777
|
- |
|
datingpro
|
matchmaking
|
SQL injection vulnerability in PG Matchmaking allows remote attackers to execute arbitrary SQL commands via the id parameter to (1) news_read.php and (2) gifts_show.php.
|
CWE-89
SQL Injection
|
CVE-2008-4665
|
2017-09-29 10:32 |
2008-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256778
|
- |
|
deeserver
|
ultimate_webboard
|
SQL injection vulnerability in webboard.php in Ultimate Webboard 3.00 allows remote attackers to execute arbitrary SQL commands via the Category parameter.
|
CWE-89
SQL Injection
|
CVE-2008-4666
|
2017-09-29 10:32 |
2008-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256779
|
- |
|
arabcms
|
arabcms
|
Directory traversal vulnerability in rss.php in ArabCMS 2.0 beta 1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the rss parameter.
|
CWE-22
Path Traversal
|
CVE-2008-4667
|
2017-09-29 10:32 |
2008-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256780
|
- |
|
joomla
|
com_imagebrowser
|
Directory traversal vulnerability in the Image Browser (com_imagebrowser) 0.1.5 component for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the fo…
|
CWE-22
Path Traversal
|
CVE-2008-4668
|
2017-09-29 10:32 |
2008-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|