256741
|
- |
|
alkalinephp
|
alkalinephp
|
AlkalinePHP 0.77.35 and earlier allows remote attackers to bypass authentication and gain administrative access by creating an admin account via a direct request to adduser.php.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-2346
|
2017-09-29 10:31 |
2008-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256742
|
- |
|
mypicgallery
|
mypicgallery
|
MyPicGallery 1.0 allows remote attackers to bypass application authentication and gain administrative access by setting the userID parameter to "admin" in a direct request to admin/addUser.php.
|
CWE-287
Improper Authentication
|
CVE-2008-2347
|
2017-09-29 10:31 |
2008-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256743
|
- |
|
meltingicefs
|
meltingice_file_system
|
MeltingIce File System 1.0 allows remote attackers to bypass application authentication, create new user accounts, and exceed application quotas via a direct request to admin/adduser.php.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-2348
|
2017-09-29 10:31 |
2008-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256744
|
- |
|
zomp
|
zomplog
|
Zomplog 3.8.2 and earlier allows remote attackers to gain administrative access by creating an admin account via a direct request to install/newuser.php with the admin parameter set to 1.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-2349
|
2017-09-29 10:31 |
2008-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256745
|
- |
|
webmanager-pro
|
cms_webmanager-pro
|
Multiple SQL injection vulnerabilities in index.php in CMS WebManager-Pro allow remote attackers to execute arbitrary SQL commands via the (1) lang_id and (2) menu_id parameters.
|
CWE-89
SQL Injection
|
CVE-2008-2351
|
2017-09-29 10:31 |
2008-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256746
|
- |
|
gnugallery
|
gnugallery
|
Directory traversal vulnerability in admin.php in GNU/Gallery 1.1.1.0 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the show parameter.
|
CWE-22
Path Traversal
|
CVE-2008-2353
|
2017-09-29 10:31 |
2008-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256747
|
- |
|
wr-script
|
wr-meeting
|
Directory traversal vulnerability in index.php in WR-Meeting 1.0, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the msn…
|
CWE-22
Path Traversal
|
CVE-2008-2355
|
2017-09-29 10:31 |
2008-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256748
|
- |
|
archangelmgt
|
archangel_weblog
|
SQL injection vulnerability in index.php in Archangel Weblog 0.90.02 and earlier allows remote attackers to execute arbitrary SQL commands via the post_id parameter.
|
CWE-89
SQL Injection
|
CVE-2008-2356
|
2017-09-29 10:31 |
2008-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256749
|
- |
|
linux
|
linux_kernel
|
Integer overflow in the dccp_feat_change function in net/dccp/feat.c in the Datagram Congestion Control Protocol (DCCP) subsystem in the Linux kernel 2.6.18, and 2.6.17 through 2.6.20, allows local u…
|
CWE-189
Numeric Errors
|
CVE-2008-2358
|
2017-09-29 10:31 |
2008-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256750
|
- |
|
linux
|
linux_kernel
|
Patch information can be found at the following location:
http://lists.debian.org/debian-security-announce/2008/msg00172.html
|
CWE-189
Numeric Errors
|
CVE-2008-2358
|
2017-09-29 10:31 |
2008-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|