256391
|
- |
|
prochatrooms
|
pro_chat_rooms
|
Cross-site scripting (XSS) vulnerability in profiles/index.php in Pro Chat Rooms 3.0.2 allows remote attackers to inject arbitrary web script or HTML via the gud parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2008-6501
|
2017-09-29 10:33 |
2009-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256392
|
- |
|
prochatrooms
|
pro_chat_rooms
|
Directory traversal vulnerability in Pro Chat Rooms 3.0.2 allows remote authenticated users to select an arbitrary local PHP script as an avatar via a .. (dot dot) in the avatar parameter, and cause …
|
CWE-22
Path Traversal
|
CVE-2008-6502
|
2017-09-29 10:33 |
2009-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256393
|
- |
|
aphpkb
|
aphpkb
|
Unrestricted file upload vulnerability in saa.php in Andy's PHP Knowledgebase (aphpkb) 0.92.9 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then …
|
CWE-94
Code Injection
|
CVE-2008-6513
|
2017-09-29 10:33 |
2009-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256394
|
- |
|
vidiscript
|
vidiscript
|
Unrestricted file upload vulnerability in the profile feature in VidiScript allows registered remote authenticated users to execute arbitrary code by uploading a PHP file as an Avatar, then accessing…
|
CWE-94
Code Injection
|
CVE-2008-6518
|
2017-09-29 10:33 |
2009-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256395
|
- |
|
imatix
|
xitami
|
Format string vulnerability in Xitami Web Server 2.2a through 2.5c2, and possibly other versions, allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary co…
|
CWE-134
Use of Externally-Controlled Format String
|
CVE-2008-6519
|
2017-09-29 10:33 |
2009-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256396
|
- |
|
cale_dunlap
|
openinvoice
|
auth.php in openInvoice 0.90 beta and earlier allows remote attackers to bypass authentication and gain privileges by setting the oiauth cookie. NOTE: this can be leveraged with a separate vulnerabi…
|
CWE-287
Improper Authentication
|
CVE-2008-6523
|
2017-09-29 10:33 |
2009-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256397
|
- |
|
cale_dunlap
|
openinvoice
|
resetpass.php in openInvoice 0.90 beta and earlier allows remote authenticated users to change the passwords of arbitrary users via a modified uid parameter. NOTE: this can be leveraged with a separ…
|
CWE-255
Credentials Management
|
CVE-2008-6524
|
2017-09-29 10:33 |
2009-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256398
|
- |
|
nicephpscripts
|
nice_php_faq_script
|
SQL injection vulnerability in the Admin Panel in Nice PHP FAQ Script (Knowledge base Script) allows remote attackers to execute arbitrary SQL commands via the Password parameter (aka the pass field).
|
CWE-89
SQL Injection
|
CVE-2008-6525
|
2017-09-29 10:33 |
2009-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256399
|
- |
|
bosdev
|
bos_classifieds
|
SQL injection vulnerability in index.php in BosDev BosClassifieds allows remote attackers to execute arbitrary SQL commands via the cat_id parameter, a different vector than CVE-2008-1838.
|
CWE-89
SQL Injection
|
CVE-2008-6526
|
2017-09-29 10:33 |
2009-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256400
|
- |
|
go4i
|
go41.net_asp_forum
|
SQL injection vulnerability in forum.asp in GO4I.NET ASP Forum 1.0 allows remote attackers to execute arbitrary SQL commands via the iFor parameter.
|
CWE-89
SQL Injection
|
CVE-2008-6527
|
2017-09-29 10:33 |
2009-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|