256901
|
- |
|
realm_project
|
realm_cms
|
SQL injection vulnerability in the KeyWordsList function in _includes/inc_routines.asp in Realm CMS 2.3 and earlier allows remote attackers to execute arbitrary SQL commands via the kwrd parameter in…
|
CWE-89
SQL Injection
|
CVE-2008-2679
|
2017-09-29 10:31 |
2008-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256902
|
- |
|
realm_project
|
realm_cms
|
Multiple cross-site scripting (XSS) vulnerabilities in _db/compact.asp in Realm CMS 2.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) CmpctedDB and (2) Boyut p…
|
CWE-79
Cross-site Scripting
|
CVE-2008-2680
|
2017-09-29 10:31 |
2008-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256903
|
- |
|
realm_project
|
realm_cms
|
Realm CMS 2.3 and earlier allows remote attackers to obtain sensitive information via a direct request to _db/compact.asp, which reveals the database path in an error message.
|
CWE-200
Information Exposure
|
CVE-2008-2681
|
2017-09-29 10:31 |
2008-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256904
|
- |
|
realm_project
|
realm_cms
|
_RealmAdmin/login.asp in Realm CMS 2.3 and earlier allows remote attackers to bypass authentication and access admin pages via certain modified cookies, probably including (1) cUserRole, (2) cUserNam…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-2682
|
2017-09-29 10:31 |
2008-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256905
|
- |
|
black_ice
|
barcode_sdk
|
The BIDIB.BIDIBCtrl.1 ActiveX control in BIDIB.ocx 10.9.3.0 in Black Ice Barcode SDK 5.01 allows remote attackers to force the download and storage of arbitrary files by specifying the origin URL in …
|
CWE-20
Improper Input Validation
|
CVE-2008-2683
|
2017-09-29 10:31 |
2008-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256906
|
- |
|
blackice
|
black_ice_barcode_sdk
|
The BIDIB.BIDIBCtrl.1 ActiveX control in BIDIB.ocx 10.9.3.0 in Black Ice Barcode SDK 5.01 allows remote attackers to execute arbitrary code via long strings in the two arguments to the DownloadImageF…
|
CWE-94
Code Injection
|
CVE-2008-2684
|
2017-09-29 10:31 |
2008-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256907
|
- |
|
flux_cms
|
flux_cms
|
webinc/bxe/scripts/loadsave.php in Flux CMS 1.5.0 and earlier allows remote attackers to execute arbitrary code by overwriting a PHP file in webinc/bxe/scripts/ via a filename in the XML parameter an…
|
CWE-20
Improper Input Validation
|
CVE-2008-2686
|
2017-09-29 10:31 |
2008-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256908
|
- |
|
promanager
|
promanager
|
Directory traversal vulnerability in inc/config.php in ProManager 0.73 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter.
|
CWE-22
Path Traversal
|
CVE-2008-2687
|
2017-09-29 10:31 |
2008-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256909
|
- |
|
pilotcart
|
pilot_cart
|
SQL injection vulnerability in pilot.asp in ASPilot Pilot Cart 7.3 allows remote attackers to execute arbitrary SQL commands via the article parameter in a kb action.
|
CWE-89
SQL Injection
|
CVE-2008-2688
|
2017-09-29 10:31 |
2008-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256910
|
- |
|
browsercrm
|
browsercrm
|
PHP remote file inclusion vulnerability in pub/clients.php in BrowserCRM 5.002.00 allows remote attackers to execute arbitrary PHP code via a URL in the bcrm_pub_root parameter.
|
CWE-94
Code Injection
|
CVE-2008-2689
|
2017-09-29 10:31 |
2008-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|