259661
|
- |
|
uebimiau
|
webmail
|
Uebimiau Webmail 2.7.10 and 2.7.2 does not protect authentication state variables from being set through HTTP requests, which allows remote attackers to bypass authentication via a sess[auth]=1 param…
|
CWE-287
Improper Authentication
|
CVE-2008-0210
|
2017-09-29 10:30 |
2008-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259662
|
- |
|
php_webquest
|
php_webquest
|
SQL injection vulnerability in soporte_horizontal_w.php in PHP Webquest 2.6 allows remote attackers to execute arbitrary SQL commands via the id_actividad parameter, a different vector than CVE-2007-…
|
CWE-89
SQL Injection
|
CVE-2008-0219
|
2017-09-29 10:30 |
2008-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259663
|
- |
|
gateway
|
cweblaunchctl_activex_control weblaunch
|
Multiple stack-based buffer overflows in the WebLaunch.WeblaunchCtl.1 (aka CWebLaunchCtl) ActiveX control in weblaunch.ocx 1.0.0.1 in Gateway Weblaunch allow remote attackers to execute arbitrary cod…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2008-0220
|
2017-09-29 10:30 |
2008-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259664
|
- |
|
gateway
|
weblaunch
|
Directory traversal vulnerability in the WebLaunch.WeblaunchCtl.1 (aka CWebLaunchCtl) ActiveX control in weblaunch.ocx 1.0.0.1 in Gateway Weblaunch allows remote attackers to execute arbitrary progra…
|
CWE-22
Path Traversal
|
CVE-2008-0221
|
2017-09-29 10:30 |
2008-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259665
|
- |
|
wordpress
|
filemanager
|
Unrestricted file upload vulnerability in ajaxfilemanager.php in the Wp-FileManager 1.2 plugin for WordPress allows remote attackers to upload and execute arbitrary PHP code via unspecified vectors.
|
CWE-94
Code Injection
|
CVE-2008-0222
|
2017-09-29 10:30 |
2008-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259666
|
- |
|
osdate
|
osdate
|
PHP remote file inclusion vulnerability in php121db.php in osDate 2.0.8 and possibly earlier versions allows remote attackers to execute arbitrary PHP code via a URL in the php121dir parameter.
|
CWE-94
Code Injection
|
CVE-2008-0230
|
2017-09-29 10:30 |
2008-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259667
|
- |
|
zero_cms
|
zero_cms
|
Multiple SQL injection vulnerabilities in Zero CMS 1.0 Alpha allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to index.php, or the (2) f or t parameters to forums/ind…
|
CWE-89
SQL Injection
|
CVE-2008-0232
|
2017-09-29 10:30 |
2008-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259668
|
- |
|
zero_cms
|
zero_cms
|
Unrestricted file upload vulnerability in Zero CMS 1.0 Alpha and earlier allows remote attackers to bypass intended access restrictions and upload and execute arbitrary files by uploading an avatar f…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-0233
|
2017-09-29 10:30 |
2008-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259669
|
- |
|
microsoft
|
vfp_ole_server_activex_control
|
The Microsoft VFP_OLE_Server ActiveX control allows remote attackers to execute arbitrary code by invoking the foxcommand method.
|
CWE-94
Code Injection
|
CVE-2008-0235
|
2017-09-29 10:30 |
2008-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259670
|
- |
|
microsoft
|
visual_foxpro
|
An ActiveX control for Microsoft Visual FoxPro (vfp6r.dll 6.0.8862.0) allows remote attackers to execute arbitrary commands by invoking the DoCmd method.
|
NVD-CWE-Other
|
CVE-2008-0236
|
2017-09-29 10:30 |
2008-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|