256481
|
- |
|
zkup
|
zkup
|
Static code injection vulnerability in admin/configuration/modifier.php in zKup CMS 2.0 through 2.3 allows remote attackers to inject arbitrary PHP code into fichiers/config.php via a null byte (%00)…
|
CWE-94
Code Injection
|
CVE-2008-7123
|
2017-09-29 10:33 |
2009-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256482
|
- |
|
zkup
|
zkup
|
zKup CMS 2.0 through 2.3 does not require administrative authentication for admin/configuration/modifier.php, which allows remote attackers to gain administrator privileges via a direct request, as d…
|
CWE-287
Improper Authentication
|
CVE-2008-7124
|
2017-09-29 10:33 |
2009-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256483
|
- |
|
icq
|
icq_toolbar
|
toolbaru.dll in ICQ Toolbar (ICQToolbar) 2.3 allows remote attackers to cause a denial of service (toolbar crash) via a long argument to the (1) RequestURL, (2) GetPropertyById, or (3) SetPropertyByI…
|
CWE-20
Improper Input Validation
|
CVE-2008-7136
|
2017-09-29 10:33 |
2009-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256484
|
- |
|
docebo
|
docebo
|
SQL injection vulnerability in the autoDetectRegion function in doceboCore/lib/lib.regset.php in Docebo 3.5.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the Accept-La…
|
CWE-89
SQL Injection
|
CVE-2008-7153
|
2017-09-29 10:33 |
2009-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256485
|
- |
|
docebo
|
docebo
|
Docebo 3.5.0.3 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) class/class.conf_fw.php, (2) class.module/class.event_manager.php, (3) lib/lib.domxml5.p…
|
CWE-200
Information Exposure
|
CVE-2008-7154
|
2017-09-29 10:33 |
2009-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256486
|
- |
|
ekinboard
|
ekinboard
|
EkinBoard 1.1.0 and earlier, when register_globals is enabled, allows remote attackers to bypass authorization and gain administrator privileges by setting the _groups[] parameter to 2, as demonstrat…
|
CWE-287
Improper Authentication
|
CVE-2008-7156
|
2017-09-29 10:33 |
2009-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256487
|
- |
|
ekinboard
|
ekinboard
|
Unrestricted file upload vulnerability in EkinBoard 1.1.0 and earlier allows remote attackers to execute arbitrary code by uploading an avatar file with an executable extension followed by a safe ext…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-7157
|
2017-09-29 10:33 |
2009-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256488
|
- |
|
sinecms
|
sinecms
|
Directory traversal vulnerability in mods/Integrated/index.php in SineCMS 2.3.5 and earlier, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via…
|
CWE-22
Path Traversal
|
CVE-2008-7163
|
2017-09-29 10:33 |
2009-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256489
|
- |
|
sami_ekblad
|
page_manager
|
Unrestricted file upload vulnerability in upload.php in Page Manager 2006-02-04 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it v…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-7167
|
2017-09-29 10:33 |
2009-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256490
|
- |
|
jabode
|
com_jabode
|
SQL injection vulnerability in Jabode horoscope extension (com_jabode) for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a sign task to index.php.
|
CWE-89
SQL Injection
|
CVE-2008-7169
|
2017-09-29 10:33 |
2009-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|