256651
|
- |
|
stormboards_aaronnemisis
|
stormboards
|
SQL injection vulnerability in thread.php in stormBoards 1.0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2008-5726
|
2017-09-29 10:32 |
2008-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256652
|
- |
|
netcat
|
netcat
|
SQL injection vulnerability in modules/auth/password_recovery.php in AIST NetCat 3.12 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the…
|
CWE-89
SQL Injection
|
CVE-2008-5727
|
2017-09-29 10:32 |
2008-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256653
|
- |
|
netcat
|
netcat
|
Multiple directory traversal vulnerabilities in AIST NetCat 3.12 and earlier, when magic_quotes_gpc is disabled and register_globals is enabled, allow remote attackers to include and execute arbitrar…
|
CWE-22
Path Traversal
|
CVE-2008-5728
|
2017-09-29 10:32 |
2008-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256654
|
- |
|
netcat
|
netcat
|
Multiple cross-site scripting (XSS) vulnerabilities in AIST NetCat 3.12 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) form and (2) control parameters to FCKedi…
|
CWE-79
Cross-site Scripting
|
CVE-2008-5729
|
2017-09-29 10:32 |
2008-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256655
|
- |
|
netcat
|
netcat
|
Multiple CRLF injection vulnerabilities in AIST NetCat 3.12 and earlier allow remote attackers to have an unknown impact via unspecified vectors involving (1) a %0a sequence in a cookie and (2) the a…
|
CWE-20
Improper Input Validation
|
CVE-2008-5730
|
2017-09-29 10:32 |
2008-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256656
|
- |
|
kafooeyblog
|
kafooeyblog
|
Unrestricted file upload vulnerability in lib/image_upload.php in KafooeyBlog 1.55b allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing …
|
CWE-20
Improper Input Validation
|
CVE-2008-5732
|
2017-09-29 10:32 |
2008-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256657
|
- |
|
nodstrum
|
mysql_calendar
|
SQL injection vulnerability in index.php in Nodstrum MySQL Calendar 1.1 and 1.2 allows remote attackers to execute arbitrary SQL commands via the username parameter.
|
CWE-89
SQL Injection
|
CVE-2008-5737
|
2017-09-29 10:32 |
2008-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256658
|
- |
|
nodstrum
|
mysql_calendar
|
Nodstrum MySQL Calendar 1.1 and 1.2 allows remote attackers to bypass authentication and gain administrative access by setting the nodstrumCalendarV2 cookie to 1. NOTE: some of these details are obt…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-5738
|
2017-09-29 10:32 |
2008-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256659
|
- |
|
pligg
|
pligg_cms
|
SQL injection vulnerability in evb/check_url.php in Pligg CMS 9.9.5 Beta allows remote attackers to execute arbitrary SQL commands via the url parameter.
|
CWE-89
SQL Injection
|
CVE-2008-5739
|
2017-09-29 10:32 |
2008-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256660
|
- |
|
netcat
|
netcat
|
Multiple open redirect vulnerabilities in AIST NetCat 3.12 and earlier allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via (1) the redirect parameter in a…
|
CWE-59
Link Following
|
CVE-2008-5742
|
2017-09-29 10:32 |
2008-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|