256671
|
- |
|
2500mhz
|
worksimple
|
WorkSimple 1.2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing usernames and passwords via a…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-5765
|
2017-09-29 10:32 |
2008-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256672
|
- |
|
fascript
|
faupload
|
SQL injection vulnerability in download.php in Farsi Script Faupload allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2008-5766
|
2017-09-29 10:32 |
2008-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256673
|
- |
|
gazatem
|
gnews_publisher
|
SQL injection vulnerability in authors.asp in gNews Publisher allows remote attackers to execute arbitrary SQL commands via the authorID parameter.
|
CWE-89
SQL Injection
|
CVE-2008-5767
|
2017-09-29 10:32 |
2008-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256674
|
- |
|
sirium
|
am_events_module
|
SQL injection vulnerability in print.php in the AM Events (aka Amevents) module 0.22 for XOOPS allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2008-5768
|
2017-09-29 10:32 |
2008-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256675
|
- |
|
phpweather
|
phpweather
|
Cross-site scripting (XSS) vulnerability in config/make_config.php in PHP Weather 2.2.2 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.
|
CWE-79
Cross-site Scripting
|
CVE-2008-5770
|
2017-09-29 10:32 |
2008-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256676
|
- |
|
phpweather
|
phpweather
|
Directory traversal vulnerability in test.php in PHP Weather 2.2.2 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the language parameter.
|
CWE-22
Path Traversal
|
CVE-2008-5771
|
2017-09-29 10:32 |
2008-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256677
|
- |
|
aspsiteware
|
realtylistings
|
Multiple SQL injection vulnerabilities in ASPSiteWare RealtyListings 1.0 and 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) iType parameter to type.asp and the (2) iPro para…
|
CWE-89
SQL Injection
|
CVE-2008-5772
|
2017-09-29 10:32 |
2008-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256678
|
- |
|
nukedit
|
nukedit
|
Nukedit 4.9.8 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing usernames and passwords via a di…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-5773
|
2017-09-29 10:32 |
2008-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256679
|
- |
|
aspsiteware
|
homebuilder
|
Multiple SQL injection vulnerabilities in ASPSiteWare HomeBuilder 1.0 and 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) iType parameter to (a) type.asp and (b) type2.asp an…
|
CWE-89
SQL Injection
|
CVE-2008-5774
|
2017-09-29 10:32 |
2008-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256680
|
- |
|
apertoblog
|
apertoblog
|
SQL injection vulnerability in categories.php in Aperto Blog 0.1.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2008-5775
|
2017-09-29 10:32 |
2008-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|