256621
|
- |
|
miniweb2
|
miniweb
|
SQL injection vulnerability in index.php in Miniweb 2.0 allows remote attackers to execute arbitrary SQL commands via the username parameter in a login action.
|
CWE-89
SQL Injection
|
CVE-2008-6582
|
2017-09-29 10:33 |
2009-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256622
|
- |
|
bsplayer
|
bs.player
|
Buffer overflow in BS.player 2.27 build 959 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in a .SRT file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2008-6583
|
2017-09-29 10:33 |
2009-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256623
|
- |
|
picoflat
|
picoflat_cms
|
Directory traversal vulnerability in index.php in PicoFlat CMS 0.5.9 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the pagina parameter, a different vulne…
|
CWE-22
Path Traversal
|
CVE-2008-6604
|
2017-09-29 10:33 |
2009-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256624
|
- |
|
2wire
|
1701hg 1800hw 2071hg 2700hg
|
Cross-site request forgery (CSRF) vulnerability in the xslt script in the web-based management interface on the 2wire 1701HG, 1800HW, 2071HG, and 2700HG with firmware 3.17.5, 3.7.1, 4.25.19, or 5.29.…
|
CWE-352
Origin Validation Error
|
CVE-2008-6605
|
2017-09-29 10:33 |
2009-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256625
|
- |
|
matpo
|
matpo_link
|
SQL injection vulnerability in view.php in MatPo Link 1.2 Beta allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2008-6606
|
2017-09-29 10:33 |
2009-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256626
|
- |
|
matpo
|
matpo_link
|
Cross-site scripting (XSS) vulnerability in view.php in MatPo Link 1.2 Beta allows remote attackers to inject arbitrary web script or HTML via the thema parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2008-6607
|
2017-09-29 10:33 |
2009-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256627
|
- |
|
developiteasy
|
events_calendar
|
Multiple SQL injection vulnerabilities in DevelopItEasy Events Calendar 1.2 allow remote attackers to execute arbitrary SQL commands via (1) the user_name parameter (aka user field) to admin/index.ph…
|
CWE-89
SQL Injection
|
CVE-2008-6608
|
2017-09-29 10:33 |
2009-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256628
|
- |
|
abweb
|
minimal_ablog
|
SQL injection vulnerability in index.php in Minimal ABlog 0.4 allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2008-6611
|
2017-09-29 10:33 |
2009-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256629
|
- |
|
abweb
|
minimal-ablog
|
Unrestricted file upload vulnerability in admin/uploader.php in Minimal ABlog 0.4 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it…
|
CWE-94
Code Injection
|
CVE-2008-6612
|
2017-09-29 10:33 |
2009-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256630
|
- |
|
abweb
|
minimal-ablog
|
uploader.php in minimal-ablog 0.4 does not properly restrict access, which allows remote attackers to gain administrative privileges via a direct request.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-6613
|
2017-09-29 10:33 |
2009-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|