259251
|
- |
|
webportal
|
webportal_cms
|
Multiple SQL injection vulnerabilities in WebPortal CMS 0.6-beta allow remote attackers to execute arbitrary SQL commands via the user_name parameter to actions.php, and unspecified other vectors.
|
CWE-89
SQL Injection
|
CVE-2008-0142
|
2017-09-29 10:30 |
2008-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259252
|
- |
|
spacial_audio_solutions
|
sam_broadcaster samphpweb
|
PHP remote file inclusion vulnerability in common/db.php in samPHPweb, possibly 4.2.2 and others, as provided with SAM Broadcaster, allows remote attackers to execute arbitrary PHP code via a URL in …
|
CWE-94
Code Injection
|
CVE-2008-0143
|
2017-09-29 10:30 |
2008-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259253
|
- |
|
phprisk
|
netrisk
|
PHP remote file inclusion vulnerability in index.php in NetRisk 1.9.7 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the page parameter. NOTE: this can also be levera…
|
CWE-89
SQL Injection
|
CVE-2008-0144
|
2017-09-29 10:30 |
2008-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259254
|
- |
|
smallnuke
|
smallnuke
|
SQL injection vulnerability in index.php in SmallNuke 2.0.4 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via (1) the user_email parameter …
|
CWE-89
SQL Injection
|
CVE-2008-0147
|
2017-09-29 10:30 |
2008-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259255
|
- |
|
evilboard
|
evilboard
|
SQL injection vulnerability in index.php in EvilBoard 0.1a (Alpha) allows remote attackers to execute arbitrary SQL commands the c parameter.
|
CWE-89
SQL Injection
|
CVE-2008-0154
|
2017-09-29 10:30 |
2008-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259256
|
- |
|
evilboard
|
evilboard
|
Cross-site scripting (XSS) vulnerability in index.php in EvilBoard 0.1a (Alpha) allows remote attackers to inject arbitrary web script or HTML via the c parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2008-0155
|
2017-09-29 10:30 |
2008-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259257
|
- |
|
flexbb
|
flexbb
|
SQL injection vulnerability in FlexBB 0.6.3 and earlier allows remote attackers to execute arbitrary SQL commands via the flexbb_temp_id parameter in a cookie.
|
CWE-89
SQL Injection
|
CVE-2008-0157
|
2017-09-29 10:30 |
2008-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259258
|
- |
|
shop-script
|
shop-script
|
Directory traversal vulnerability in index.php in Shop-Script 2.0 and possibly other versions allows remote attackers to read arbitrary files via a .. (dot dot) in the aux_page parameter.
|
CWE-22
Path Traversal
|
CVE-2008-0158
|
2017-09-29 10:30 |
2008-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259259
|
- |
|
eggblog
|
eggblog
|
SQL injection vulnerability in index.php in eggBlog 3.1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the eggblogpassword parameter in a cookie.
|
CWE-89
SQL Injection
|
CVE-2008-0159
|
2017-09-29 10:30 |
2008-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259260
|
- |
|
spacial_audio_solutions
|
samphpweb
|
SQL injection vulnerability in songinfo.php in SAM Broadcaster samPHPweb, possibly 4.2.2 and earlier, allows remote attackers to execute arbitrary SQL commands via the songid parameter.
|
CWE-89
SQL Injection
|
CVE-2008-0187
|
2017-09-29 10:30 |
2008-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|