256421
|
- |
|
2532gigs
|
2532gigs
|
2532designs 2532|Gigs 1.2.2 and earlier allows remote attackers to trigger a backup and obtain sensitive information via a direct request to backup.php, which creates backup.sql under the web root wi…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-6199
|
2017-09-29 10:33 |
2009-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256422
|
- |
|
2532gigs
|
2532gigs
|
Reference links indicate attacker must be authenticated for attack to be successful.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-6199
|
2017-09-29 10:33 |
2009-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256423
|
- |
|
jakob-persson
|
cobalt
|
SQL injection vulnerability in CoBaLT 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter to (1) urun.asp, (2) admin/bayi_listele.asp, (3) admin/urun_grup_listele.asp, …
|
CWE-89
SQL Injection
|
CVE-2008-6202
|
2017-09-29 10:33 |
2009-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256424
|
- |
|
supernet
|
supernet_shop
|
Multiple SQL injection vulnerabilities in SuperNET Shop 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to secure/admin/guncelle.asp, (2) kulad and s…
|
CWE-89
SQL Injection
|
CVE-2008-6204
|
2017-09-29 10:33 |
2009-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256425
|
- |
|
vastal
|
software_zone
|
SQL injection vulnerability in view_product.php in Vastal I-Tech Software Zone allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.
|
CWE-89
SQL Injection
|
CVE-2008-6209
|
2017-09-29 10:33 |
2009-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256426
|
- |
|
dream4
|
koobi
|
SQL injection vulnerability in index.php in dream4 Koobi 4.4 and 5.4 allows remote attackers to execute arbitrary SQL commands via the img_id parameter in the gallerypic page.
|
CWE-89
SQL Injection
|
CVE-2008-6210
|
2017-09-29 10:33 |
2009-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256427
|
- |
|
harlandscripts
|
pro_traffic_one
|
SQL injection vulnerability in mypage.php in Harlandscripts Pro Traffic One allows remote attackers to execute arbitrary SQL commands via the trg parameter.
|
CWE-89
SQL Injection
|
CVE-2008-6213
|
2017-09-29 10:33 |
2009-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256428
|
- |
|
harlandscripts
|
pro_traffic_one
|
SQL injection vulnerability in poll_results.php in Harlandscripts Pro Traffic One allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2008-6214
|
2017-09-29 10:33 |
2009-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256429
|
- |
|
bookingcentre
|
booking_system_for_hotels_group
|
Cross-site scripting (XSS) vulnerability in cadena_ofertas_ext.php in Venalsur Booking Centre Booking System for Hotels Group allows remote attackers to inject arbitrary web script or HTML via the Of…
|
CWE-79
Cross-site Scripting
|
CVE-2008-6215
|
2017-09-29 10:33 |
2009-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256430
|
- |
|
bookingcentre
|
booking_system_for_hotels_group
|
SQL injection vulnerability in cadena_ofertas_ext.php in Venalsur Booking Centre Booking System for Hotels Group allows remote attackers to execute arbitrary SQL commands via the OfertaID parameter.
|
CWE-89
SQL Injection
|
CVE-2008-6216
|
2017-09-29 10:33 |
2009-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|