257201
|
- |
|
123flashchat e107
|
123_flash_chat_module e107
|
PHP remote file inclusion vulnerability in 123flashchat.php in the 123 Flash Chat 6.8.0 module for e107, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a …
|
CWE-94
Code Injection
|
CVE-2008-1989
|
2017-09-29 10:30 |
2008-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257202
|
- |
|
qemu
|
qemu
|
The drive_init function in QEMU 0.9.1 determines the format of a raw disk image based on the header, which allows local guest users to read arbitrary files on the host by modifying the header to iden…
|
CWE-200
Information Exposure
|
CVE-2008-2004
|
2017-09-29 10:30 |
2008-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257203
|
- |
|
postnuke_software_foundation
|
postschedule
|
SQL injection vulnerability in index.php in the PostSchedule 1.0 module for PostNuke allows remote attackers to execute arbitrary SQL commands via the eid parameter in an event action.
|
CWE-89
SQL Injection
|
CVE-2008-2012
|
2017-09-29 10:30 |
2008-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257204
|
- |
|
pnflashgames
|
pnflashgames
|
SQL injection vulnerability in index.php in the pnFlashGames 1.5 through 2.5 module for PostNuke, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the …
|
CWE-89
SQL Injection
|
CVE-2008-2013
|
2017-09-29 10:30 |
2008-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257205
|
- |
|
watchfire
|
appscan
|
Multiple absolute path traversal vulnerabilities in certain ActiveX controls in WatchFire AppScan 7.0 allow remote attackers to create or overwrite arbitrary files via a full pathname in the argument…
|
CWE-22
Path Traversal
|
CVE-2008-2015
|
2017-09-29 10:30 |
2008-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257206
|
- |
|
phpizabi
|
phpizabi
|
The AssignUser function in template.class.php in PHPizabi 0.848b C1 HFP3 performs unsafe macro expansions on strings delimited by '{' and '}' characters, which allows remote authenticated users to ob…
|
CWE-200
Information Exposure
|
CVE-2008-2018
|
2017-09-29 10:30 |
2008-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257207
|
- |
|
pd9_software
|
megabbs
|
Mulatiple cross-site scripting (XSS) vulnerabilities in PD9 Software MegaBBS 2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) toid parameter to send-private-message.asp a…
|
CWE-79
Cross-site Scripting
|
CVE-2008-2022
|
2017-09-29 10:30 |
2008-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257208
|
- |
|
pd9_software
|
megabbs
|
Multiple SQL injection vulnerabilities in PD9 Software MegaBBS 2.2 allow remote attackers to execute arbitrary SQL commands via the (1) invisible and (2) timeoffset parameters to profile/controlpanel…
|
CWE-89
SQL Injection
|
CVE-2008-2023
|
2017-09-29 10:30 |
2008-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257209
|
- |
|
minibb
|
minibb
|
Cross-site scripting (XSS) vulnerability in index.php in miniBB 2.2, and possibly earlier, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the gla…
|
CWE-79
Cross-site Scripting
|
CVE-2008-2024
|
2017-09-29 10:30 |
2008-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257210
|
- |
|
minibb
|
minibb
|
miniBB 2.2, and possibly earlier, when register_globals is enabled, allows remote attackers to obtain the full path via a direct request to the glang parameter in a registernew action to index.php, w…
|
CWE-200
Information Exposure
|
CVE-2008-2028
|
2017-09-29 10:30 |
2008-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|