256581
|
- |
|
dotnetindex
|
professional_download_assistant
|
Professional Download Assistant 0.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-5572
|
2017-09-29 10:32 |
2008-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256582
|
- |
|
adcomplete
|
poll_pro
|
SQL injection vulnerability in the login feature in Poll Pro 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) Password and (2) username parameters.
|
CWE-89
SQL Injection
|
CVE-2008-5573
|
2017-09-29 10:32 |
2008-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256583
|
- |
|
unscripts
|
webmaster_marketplace
|
SQL injection vulnerability in member.php in Webmaster Marketplace allows remote attackers to execute arbitrary SQL commands via the u parameter.
|
CWE-89
SQL Injection
|
CVE-2008-5574
|
2017-09-29 10:32 |
2008-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256584
|
- |
|
scssboard
|
scssboard
|
admin/forums.php in sCssBoard 1.0, 1.1, 1.11, and 1.12 allows remote attackers to bypass authentication and gain administrative access via a large value of the current_user[users_level] parameter.
|
CWE-287
Improper Authentication
|
CVE-2008-5576
|
2017-09-29 10:32 |
2008-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256585
|
- |
|
scssboard
|
scssboard
|
PHP remote file inclusion vulnerability in index.php in sCssBoard 1.0, 1.1, 1.11, and 1.12 allows remote attackers to execute arbitrary PHP code via a URL in the inc_function parameter.
|
CWE-94
Code Injection
|
CVE-2008-5577
|
2017-09-29 10:32 |
2008-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256586
|
- |
|
scssboard
|
scssboard
|
Multiple SQL injection vulnerabilities in index.php in sCssBoard 1.0, 1.1, 1.11, and 1.12 allow remote attackers to execute arbitrary SQL commands via (1) the f parameter in a showforum action, (2) t…
|
CWE-89
SQL Injection
|
CVE-2008-5578
|
2017-09-29 10:32 |
2008-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256587
|
- |
|
nukedit
|
nukedit
|
SQL injection vulnerability in utilities/login.asp in Nukedit 4.9.x, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the email parameter.
|
CWE-89
SQL Injection
|
CVE-2008-5582
|
2017-09-29 10:32 |
2008-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256588
|
- |
|
lcxbbportal
|
lcxbbportal
|
Multiple PHP remote file inclusion vulnerabilities in lcxBBportal 0.1 Alpha 2 allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter to (1) portal/includes/po…
|
CWE-94
Code Injection
|
CVE-2008-5585
|
2017-09-29 10:32 |
2008-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256589
|
- |
|
check_up
|
check_new
|
SQL injection vulnerability in findoffice.php in Check Up New Generation (aka Check New) 4.52, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the sea…
|
CWE-89
SQL Injection
|
CVE-2008-5586
|
2017-09-29 10:32 |
2008-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256590
|
- |
|
phppgadmin
|
phppgadmin
|
Directory traversal vulnerability in libraries/lib.inc.php in phpPgAdmin 4.2.1 and earlier, when register_globals is enabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the…
|
CWE-22
Path Traversal
|
CVE-2008-5587
|
2017-09-29 10:32 |
2008-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|