256741
|
- |
|
aiocp
|
aiocp
|
SQL injection vulnerability in public/code/cp_polls_results.php in All In One Control Panel (AIOCP) 1.4 allows remote attackers to execute arbitrary SQL commands via the poll_id parameter.
|
CWE-89
SQL Injection
|
CVE-2008-4782
|
2017-09-29 10:32 |
2008-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256742
|
- |
|
easy-script
|
tlads
|
tlAds 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the tlAds_login cookie to "admin."
|
CWE-287
Improper Authentication
|
CVE-2008-4783
|
2017-09-29 10:32 |
2008-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256743
|
- |
|
aflog
|
aflog
|
aflog 1.01 allows remote attackers to bypass authentication and gain administrative access by setting the aflog_auth_a cookie to "A" or "O" in (1) edit_delete.php, (2) edit_cat.php, (3) edit_lock.php…
|
CWE-287
Improper Authentication
|
CVE-2008-4784
|
2017-09-29 10:32 |
2008-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256744
|
- |
|
e107
|
alternate_profiles_plugin
|
SQL injection vulnerability in newuser.php in the alternate_profiles plugin, possibly 0.2, for e107 allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2008-4785
|
2017-09-29 10:32 |
2008-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256745
|
- |
|
e107
|
easyshop_plugin
|
SQL injection vulnerability in easyshop.php in the EasyShop plugin for e107 allows remote attackers to execute arbitrary SQL commands via the category_id parameter.
|
CWE-89
SQL Injection
|
CVE-2008-4786
|
2017-09-29 10:32 |
2008-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256746
|
- |
|
sepal
|
spboard
|
board.cgi in Sepal SPBOARD 4.5 allows remote attackers to execute arbitrary commands via shell metacharacters in the file parameter during a down_file action.
|
NVD-CWE-noinfo
|
CVE-2008-4873
|
2017-09-29 10:32 |
2008-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256747
|
- |
|
mywebcards
|
webcards
|
SQL injection vulnerability in admin.php in WebCards 1.3, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the user parameter. NOTE: some of these det…
|
CWE-89
SQL Injection
|
CVE-2008-4877
|
2017-09-29 10:32 |
2008-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256748
|
- |
|
mywebcards
|
webcards
|
Unrestricted file upload vulnerability in the "Add Image Macro" feature in WebCards 1.3 allows remote authenticated administrators to execute arbitrary code by uploading a file with an executable ext…
|
CWE-20
Improper Input Validation
|
CVE-2008-4878
|
2017-09-29 10:32 |
2008-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256749
|
- |
|
maran
|
php_shop
|
SQL injection vulnerability in prod.php in Maran PHP Shop allows remote attackers to execute arbitrary SQL commands via the cat parameter, a different vector than CVE-2008-4880.
|
CWE-89
SQL Injection
|
CVE-2008-4879
|
2017-09-29 10:32 |
2008-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256750
|
- |
|
maran
|
php_shop
|
SQL injection vulnerability in prodshow.php in Maran PHP Shop allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2008-4879.
|
CWE-89
SQL Injection
|
CVE-2008-4880
|
2017-09-29 10:32 |
2008-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|