261901
|
- |
|
modxcms
|
modxcms
|
Multiple cross-site scripting (XSS) vulnerabilities in MODx before 0.9.6.3 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) the preserveUrls function and (2) "…
|
CWE-79
Cross-site Scripting
|
CVE-2008-5942
|
2017-08-8 10:33 |
2009-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261902
|
- |
|
navboard
|
navboard
|
Multiple directory traversal vulnerabilities in NavBoard 16 (2.6.0) allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the module parameter to (1) admin_modules…
|
CWE-22
Path Traversal
|
CVE-2008-5943
|
2017-08-8 10:33 |
2009-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261903
|
- |
|
navboard
|
navboard
|
Cross-site scripting (XSS) vulnerability in modules.php in NavBoard 16 (2.6.0) allows remote attackers to inject arbitrary web script or HTML via the module parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2008-5944
|
2017-08-8 10:33 |
2009-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261904
|
- |
|
nukevietcms
|
nukeviet
|
Nukeviet 2.0 Beta allows remote attackers to bypass authentication and gain administrative access by setting the admf cookie to 1. NOTE: the provenance of this information is unknown; the details ar…
|
CWE-287
Improper Authentication
|
CVE-2008-5945
|
2017-08-8 10:33 |
2009-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261905
|
- |
|
php-fusion
|
php-fusion
|
SQL injection vulnerability in readmore.php in PHP-Fusion 4.01 allows remote attackers to execute arbitrary SQL commands via the news_id parameter.
|
CWE-89
SQL Injection
|
CVE-2008-5946
|
2017-08-8 10:33 |
2009-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261906
|
- |
|
yapbb
|
yapbb
|
PHP remote file inclusion vulnerability in include/class_yapbbcooker.php in YapBB 1.2.Beta 2 allows remote attackers to execute arbitrary PHP code via a URL in the cfgIncludeDirectory parameter.
|
CWE-94
Code Injection
|
CVE-2008-5947
|
2017-08-8 10:33 |
2009-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261907
|
- |
|
ktp_computer_customer_database
|
ktp_computer_customer_database
|
SQL injection vulnerability in KTP Computer Customer Database (KTPCCD) CMS, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the lname parameter in a l…
|
CWE-89
SQL Injection
|
CVE-2008-5954
|
2017-08-8 10:33 |
2009-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261908
|
- |
|
i-netsolution
|
orkut_clone
|
SQL injection vulnerability in profile_social.php in i-Net Solution Orkut Clone allows remote authenticated users to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2008-5970
|
2017-08-8 10:33 |
2009-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261909
|
- |
|
i-netsolution
|
orkut_clone
|
Cross-site scripting (XSS) vulnerability in profile_social.php in i-Net Solution Orkut Clone allows remote authenticated users to inject arbitrary web script or HTML via the id parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2008-5971
|
2017-08-8 10:33 |
2009-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261910
|
- |
|
activewebsoftwares
|
active_price_comparison
|
SQL injection vulnerability in links.asp in Active Price Comparison 4.0 allows remote attackers to execute arbitrary SQL commands via the linkid parameter. NOTE: the provenance of this information i…
|
CWE-89
SQL Injection
|
CVE-2008-5975
|
2017-08-8 10:33 |
2009-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|