256471
|
- |
|
businessvein
|
php_tv_portal
|
SQL injection vulnerability in index.php in PHP TV Portal 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the mid parameter.
|
CWE-89
SQL Injection
|
CVE-2008-6285
|
2017-09-29 10:33 |
2009-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256472
|
- |
|
activewebsoftwares
|
active_newsletter
|
Multiple SQL injection vulnerabilities in SubscriberStart.asp in Active Newsletter 4.3 allow remote attackers to execute arbitrary SQL commands via (1) the email parameter (aka username or E-mail fie…
|
CWE-89
SQL Injection
|
CVE-2008-6286
|
2017-09-29 10:33 |
2009-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256473
|
- |
|
getmiro
|
broadcast_machine
|
Multiple PHP remote file inclusion vulnerabilities in Broadcast Machine 0.1 allow remote attackers to execute arbitrary PHP code via a URL in the baseDir parameter to (1) MySQLController.php, (2) SQL…
|
CWE-94
Code Injection
|
CVE-2008-6287
|
2017-09-29 10:33 |
2009-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256474
|
- |
|
interface-medien
|
ibase
|
Directory traversal vulnerability in download.php in Interface Medien ibase 2.03 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter.
|
CWE-22
Path Traversal
|
CVE-2008-6288
|
2017-09-29 10:33 |
2009-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256475
|
- |
|
toursmanager
|
tours_manager
|
SQL injection vulnerability in cityview.php in Tours Manager 1.0 allows remote attackers to execute arbitrary SQL commands via the cityid parameter.
|
CWE-89
SQL Injection
|
CVE-2008-6289
|
2017-09-29 10:33 |
2009-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256476
|
- |
|
niclor
|
include_sito
|
Directory traversal vulnerability in includefile.php in nicLOR Sito, when register_globals is enabled or magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary files v…
|
CWE-22
Path Traversal
|
CVE-2008-6290
|
2017-09-29 10:33 |
2009-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256477
|
- |
|
accscripts
|
acc_php_email
|
Acc PHP eMail 1.1 allows remote attackers to bypass authentication and gain administrative access by setting the NEWSLETTERLOGIN cookie to "admin".
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-6291
|
2017-09-29 10:33 |
2009-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256478
|
- |
|
accscripts
|
acc_autos
|
Acc Autos 4.0 allows remote attackers to bypass authentication and gain administrative access by setting the (1) username_cookie to "admin," (2) right_cookie to "1," and (3) id_cookie to "1."
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-6292
|
2017-09-29 10:33 |
2009-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256479
|
- |
|
accscripts
|
acc_real_estate
|
admin/Index.php in Acc Real Estate 4.0 allows remote attackers to bypass authentication and gain administrative access by setting the username_cookie to "admin."
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-6293
|
2017-09-29 10:33 |
2009-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256480
|
- |
|
accscripts
|
acc_statistics
|
admin/Index.php in Acc Statistics 1.1 allows remote attackers to bypass authentication and gain administrative access by setting the username_cookie cookie to "admin."
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-6294
|
2017-09-29 10:33 |
2009-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|