258751
|
- |
|
preproject
|
pre_survey_poll
|
SQL injection vulnerability in default.asp in Pre Survey Poll allows remote attackers to execute arbitrary SQL commands via the catid parameter.
|
CWE-89
SQL Injection
|
CVE-2008-3310
|
2017-09-29 10:31 |
2008-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258752
|
- |
|
maian_script_world
|
maian_search
|
admin/index.php in Maian Search 1.1 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitrary search_cookie cookie.
|
CWE-287
Improper Authentication
|
CVE-2008-3317
|
2017-09-29 10:31 |
2008-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258753
|
- |
|
mantis
|
mantis
|
Cross-site scripting (XSS) vulnerability in return_dynamic_filters.php in Mantis before 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the filter_target parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2008-3331
|
2017-09-29 10:31 |
2008-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258754
|
- |
|
mantis
|
mantis
|
http://marc.info/?l=bugtraq&m=121130774617956&w=4
"We have found an XSS vulnerability in return_dynamic_filters.php. In
order to exploit this vulnerability the attacker must be authenticated.
Us…
|
CWE-79
Cross-site Scripting
|
CVE-2008-3331
|
2017-09-29 10:31 |
2008-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258755
|
- |
|
mantis
|
mantis
|
Eval injection vulnerability in adm_config_set.php in Mantis before 1.1.2 allows remote authenticated administrators to execute arbitrary code via the value parameter.
|
CWE-94
Code Injection
|
CVE-2008-3332
|
2017-09-29 10:31 |
2008-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258756
|
- |
|
e-topbiz
|
shopcart_dx
|
SQL injection vulnerability in product_detail.php in ShopCart DX allows remote attackers to execute arbitrary SQL commands via the pid parameter.
|
CWE-89
SQL Injection
|
CVE-2008-3346
|
2017-09-29 10:31 |
2008-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258757
|
- |
|
atomphotoblog
|
atomphotoblog
|
SQL injection vulnerability in atomPhotoBlog.php in Atom PhotoBlog 1.0.9.1 and 1.1.5b1 allows remote attackers to execute arbitrary SQL commands via the photoId parameter in a show action.
|
CWE-89
SQL Injection
|
CVE-2008-3351
|
2017-09-29 10:31 |
2008-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258758
|
- |
|
nersoft
|
live_music_plus
|
SQL injection vulnerability in index.php in Live Music Plus 1.1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a Singer action.
|
CWE-89
SQL Injection
|
CVE-2008-3352
|
2017-09-29 10:31 |
2008-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258759
|
- |
|
camera_life
|
camera_life
|
SQL injection vulnerability in sitemap.xml.php in Camera Life 2.6.2 allows remote attackers to execute arbitrary SQL commands via the id parameter in a photos action.
|
CWE-89
SQL Injection
|
CVE-2008-3355
|
2017-09-29 10:31 |
2008-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258760
|
- |
|
intellitamper
|
intellitamper
|
Stack-based buffer overflow in the HTML parser in IntelliTamper 2.0.7 allows remote attackers to execute arbitrary code via a long URL in the HREF attribute of an A element, a different vulnerability…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2008-3360
|
2017-09-29 10:31 |
2008-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|