256701
|
- |
|
phpalumni
|
phpalumni
|
SQL injection vulnerability in Acomment.php in phpAlumni allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2008-5815
|
2017-09-29 10:32 |
2009-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256702
|
- |
|
ilias
|
ilias
|
SQL injection vulnerability in repository.php in ILIAS 3.7.4 and earlier allows remote attackers to execute arbitrary SQL commands via the ref_id parameter.
|
CWE-89
SQL Injection
|
CVE-2008-5816
|
2017-09-29 10:32 |
2009-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256703
|
- |
|
web_scribble_solutions
|
webclassifieds
|
Multiple SQL injection vulnerabilities in index.php in Web Scribble Solutions webClassifieds 2005 allow remote attackers to execute arbitrary SQL commands via the (1) user and (2) password fields in …
|
CWE-89
SQL Injection
|
CVE-2008-5817
|
2017-09-29 10:32 |
2009-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256704
|
- |
|
edreamers
|
edcontainer
|
Directory traversal vulnerability in index.php in eDreamers eDContainer 2.22, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot…
|
CWE-22
Path Traversal
|
CVE-2008-5818
|
2017-09-29 10:32 |
2009-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256705
|
- |
|
edreamers
|
ednews
|
Directory traversal vulnerability in eDNews_archive.php in eDreamers eDNews 2, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot do…
|
CWE-22
Path Traversal
|
CVE-2008-5819
|
2017-09-29 10:32 |
2009-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256706
|
- |
|
edreamers
|
ednews
|
SQL injection vulnerability in eDNews_view.php in eDreamers eDNews 2 allows remote attackers to execute arbitrary SQL commands via the newsid parameter.
|
CWE-89
SQL Injection
|
CVE-2008-5820
|
2017-09-29 10:32 |
2009-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256707
|
- |
|
phpicalendar
|
phpicalendar phpicalendar2.0
|
PHP iCalendar 2.24 and earlier allows remote attackers to bypass authentication by setting the phpicalendar and phpicalendar_login cookies to 1.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-5840
|
2017-09-29 10:32 |
2009-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256708
|
- |
|
igamingcms
|
igaming_cms
|
Multiple SQL injection vulnerabilities in iGaming 1.5 and earlier allow remote attackers to execute arbitrary SQL commands via the browse parameter to (1) previews.php and (2) reviews.php, and the (3…
|
CWE-89
SQL Injection
|
CVE-2008-5841
|
2017-09-29 10:32 |
2009-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256709
|
- |
|
constructr
|
constructr-cms
|
Constructr CMS 3.02.5 and earlier stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain sensitive information by reading the hash column.
|
CWE-255
Credentials Management
|
CVE-2008-5847
|
2017-09-29 10:32 |
2009-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256710
|
- |
|
mypbs
|
mypbs
|
SQL injection vulnerability in index.php in My PHP Baseball Stats (MyPBS) allows remote attackers to execute arbitrary SQL commands via the seasonID parameter.
|
CWE-89
SQL Injection
|
CVE-2008-5851
|
2017-09-29 10:32 |
2009-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|