256601
|
- |
|
phpmygallery
|
phpmygallery
|
Directory traversal vulnerability in index.php in PHPmyGallery 1.51 gold allows remote attackers to list arbitrary directories via a .. (dot dot) in the group parameter.
|
CWE-22
Path Traversal
|
CVE-2008-5598
|
2017-09-29 10:32 |
2008-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256602
|
- |
|
merlix
|
teamworx_server
|
SQL injection vulnerability in default.asp in Merlix Teamworx Server allows remote attackers to execute arbitrary SQL commands via the password parameter (aka passwd field) in a login action. NOTE: …
|
CWE-89
SQL Injection
|
CVE-2008-5599
|
2017-09-29 10:32 |
2008-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256603
|
- |
|
merlix
|
teamworx_server
|
Merlix Teamworx Server stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for teamworx.…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-5600
|
2017-09-29 10:32 |
2008-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256604
|
- |
|
robs-projects
|
asp_user_engine
|
User Engine Lite ASP stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for users.mdb.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-5601
|
2017-09-29 10:32 |
2008-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256605
|
- |
|
natterchat
|
natterchat
|
Natterchat 1.12 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for natterchat112.md…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-5602
|
2017-09-29 10:32 |
2008-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256606
|
- |
|
aspapps
|
aspticker
|
ASPTicker 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for news.mdb.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-5603
|
2017-09-29 10:32 |
2008-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256607
|
- |
|
drennansoft
|
my_simple_forum
|
Directory traversal vulnerability in index.php in My Simple Forum 3.0 and 4.1, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot do…
|
CWE-22
Path Traversal
|
CVE-2008-5604
|
2017-09-29 10:32 |
2008-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256608
|
- |
|
aspapps
|
aspportal
|
Multiple SQL injection vulnerabilities in ASP Portal allow remote attackers to execute arbitrary SQL commands via the (1) ItemID parameter to classifieds.asp and the (2) ID parameter to Events.asp.
|
CWE-89
SQL Injection
|
CVE-2008-5605
|
2017-09-29 10:32 |
2008-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256609
|
- |
|
gazatem_technologies
|
qmail_mailing_list_manager
|
Gazatem QMail Mailing List Manager 1.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct reque…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-5606
|
2017-09-29 10:32 |
2008-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256610
|
- |
|
joomitaly
|
jmovies
|
SQL injection vulnerability in the JMovies (aka JM or com_jmovies) component 1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.
|
CWE-89
SQL Injection
|
CVE-2008-5607
|
2017-09-29 10:32 |
2008-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|