256951
|
- |
|
carlos_desseno
|
youtube_blog
|
Cross-site scripting (XSS) vulnerability in mensaje.php in C. Desseno YouTube Blog (ytb) 0.1 allows remote attackers to inject arbitrary web script or HTML via the m parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2008-3305
|
2017-09-29 10:31 |
2008-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256952
|
- |
|
youtube_blog
|
youtube_blog
|
SQL injection vulnerability in todos.php in C. Desseno YouTube Blog (ytb) 0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2008-3306.
|
CWE-89
SQL Injection
|
CVE-2008-3307
|
2017-09-29 10:31 |
2008-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256953
|
- |
|
carlos_desseno
|
youtube_blog
|
PHP remote file inclusion vulnerability in cuenta/cuerpo.php in C. Desseno YouTube Blog (ytb) 0.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in…
|
CWE-94
Code Injection
|
CVE-2008-3308
|
2017-09-29 10:31 |
2008-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256954
|
- |
|
digiappz
|
digileave
|
SQL injection vulnerability in info_book.asp in DigiLeave 1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the book_id parameter.
|
CWE-89
SQL Injection
|
CVE-2008-3309
|
2017-09-29 10:31 |
2008-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256955
|
- |
|
preproject
|
pre_survey_poll
|
SQL injection vulnerability in default.asp in Pre Survey Poll allows remote attackers to execute arbitrary SQL commands via the catid parameter.
|
CWE-89
SQL Injection
|
CVE-2008-3310
|
2017-09-29 10:31 |
2008-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256956
|
- |
|
maian_script_world
|
maian_search
|
admin/index.php in Maian Search 1.1 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitrary search_cookie cookie.
|
CWE-287
Improper Authentication
|
CVE-2008-3317
|
2017-09-29 10:31 |
2008-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256957
|
- |
|
mantis
|
mantis
|
Cross-site scripting (XSS) vulnerability in return_dynamic_filters.php in Mantis before 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the filter_target parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2008-3331
|
2017-09-29 10:31 |
2008-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256958
|
- |
|
mantis
|
mantis
|
http://marc.info/?l=bugtraq&m=121130774617956&w=4
"We have found an XSS vulnerability in return_dynamic_filters.php. In
order to exploit this vulnerability the attacker must be authenticated.
Us…
|
CWE-79
Cross-site Scripting
|
CVE-2008-3331
|
2017-09-29 10:31 |
2008-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256959
|
- |
|
mantis
|
mantis
|
Eval injection vulnerability in adm_config_set.php in Mantis before 1.1.2 allows remote authenticated administrators to execute arbitrary code via the value parameter.
|
CWE-94
Code Injection
|
CVE-2008-3332
|
2017-09-29 10:31 |
2008-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256960
|
- |
|
e-topbiz
|
shopcart_dx
|
SQL injection vulnerability in product_detail.php in ShopCart DX allows remote attackers to execute arbitrary SQL commands via the pid parameter.
|
CWE-89
SQL Injection
|
CVE-2008-3346
|
2017-09-29 10:31 |
2008-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|