256731
|
- |
|
roticv
|
rantx
|
The admin.php file in Rantx allows remote attackers to bypass authentication and gain privileges by setting the logininfo cookie to "<?php" or "?>", which is present in the password file and probably…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-2297
|
2017-09-29 10:31 |
2008-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256732
|
- |
|
sourceforge
|
web_slider
|
Admin.php in Web Slider 0.6 allows remote attackers to bypass authentication and gain privileges by setting the admin cookie to 1.
|
CWE-287
Improper Authentication
|
CVE-2008-2298
|
2017-09-29 10:31 |
2008-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256733
|
- |
|
vastal
|
phpvid
|
Cross-site scripting (XSS) vulnerability in search_results.php in Vastal I-Tech phpVID 1.1 and 1.2 allows remote attackers to inject arbitrary web script or HTML via the query parameter. NOTE: some …
|
CWE-79
Cross-site Scripting
|
CVE-2008-2335
|
2017-09-29 10:31 |
2008-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256734
|
- |
|
68_classifieds
|
68_classifieds
|
SQL injection vulnerability in category.php in 68 Classifieds 4.0.1 allows remote attackers to execute arbitrary SQL commands via the cat parameter.
|
CWE-89
SQL Injection
|
CVE-2008-2336
|
2017-09-29 10:31 |
2008-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256735
|
- |
|
imgallery
|
imgallery
|
Multiple SQL injection vulnerabilities in IMGallery 2.5, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) kategoria parameter to (a) galeria.php…
|
CWE-89
SQL Injection
|
CVE-2008-2337
|
2017-09-29 10:31 |
2008-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256736
|
- |
|
interspire
|
activekb
|
Interspire ActiveKB 1.5 and earlier allows remote attackers to gain privileges by setting the auth cookie to true when accessing unspecified scripts in /admin.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-2338
|
2017-09-29 10:31 |
2008-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256737
|
- |
|
news_manager
|
news_manager
|
Multiple SQL injection vulnerabilities in News Manager 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) lang parameter to (a) advsearch.php, (b) archive.php, and (c) index.php…
|
CWE-89
SQL Injection
|
CVE-2008-2340
|
2017-09-29 10:31 |
2008-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256738
|
- |
|
avalonnet
|
news_manager
|
PHP remote file inclusion vulnerability in ch_readalso.php in News Manager 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the read_xml_include parameter.
|
CWE-94
Code Injection
|
CVE-2008-2341
|
2017-09-29 10:31 |
2008-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256739
|
- |
|
news_manager
|
news_manager
|
Directory traversal vulnerability in attachments.php in News Manager 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the id parameter.
|
CWE-22
Path Traversal
|
CVE-2008-2342
|
2017-09-29 10:31 |
2008-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256740
|
- |
|
news_manager
|
news_manager
|
News Manager 2.0 allows remote attackers to bypass restrictions and obtain sensitive information via a direct request to (1) db/connect_str.php and (2) login/info.php.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-2343
|
2017-09-29 10:31 |
2008-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|