259401
|
- |
|
easyscripts
|
tr_script_news
|
Unrestricted file upload vulnerability in the ajout_cat mode in admin/main.php in Tr Script News 2.1 allows remote authenticated users to execute arbitrary code by uploading a file with a .php extens…
|
CWE-94
Code Injection
|
CVE-2008-1958
|
2017-09-29 10:30 |
2008-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259402
|
- |
|
php_resource
|
voice_of_web_allmyguests
|
SQL injection vulnerability in index.php in Voice Of Web AllMyGuests 0.4.1 allows remote attackers to execute arbitrary SQL commands via the AMG_id parameter in a comments action.
|
CWE-89
SQL Injection
|
CVE-2008-1961
|
2017-09-29 10:30 |
2008-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259403
|
- |
|
chimaera
|
aterr
|
Multiple directory traversal vulnerabilities in Aterr 0.9.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) class parameter to include/functions.inc.…
|
CWE-22
Path Traversal
|
CVE-2008-1962
|
2017-09-29 10:30 |
2008-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259404
|
- |
|
quate
|
grape_web_statistics
|
PHP remote file inclusion vulnerability in includes/functions.php in Quate Grape Web Statistics 0.2a allows remote attackers to execute arbitrary PHP code via a URL in the location parameter.
|
CWE-94
Code Injection
|
CVE-2008-1963
|
2017-09-29 10:30 |
2008-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259405
|
- |
|
phphq
|
phshoutbox_final
|
phShoutBox Final 1.5 and earlier only checks passwords when specified in $_POST, which allows remote attackers to gain privileges by setting the (1) phadmin cookie to admin.php, or (2) in 1.4 and ear…
|
CWE-287
Improper Authentication
|
CVE-2008-1971
|
2017-09-29 10:30 |
2008-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259406
|
- |
|
artur_sikora
|
subedit_player
|
Heap-based buffer overflow in SubEdit Player build 4056 and 4066 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long subtitle file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2008-1973
|
2017-09-29 10:30 |
2008-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259407
|
- |
|
cogites
|
e_reserve
|
SQL injection vulnerability in index.php in E-RESERV 2.1 allows remote attackers to execute arbitrary SQL commands via the ID_loc parameter.
|
CWE-89
SQL Injection
|
CVE-2008-1975
|
2017-09-29 10:30 |
2008-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259408
|
- |
|
wordpress
|
wpss
|
SQL injection vulnerability in ss_load.php in the Spreadsheet (wpSS) 0.6 and earlier plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the ss_id parameter.
|
CWE-89
SQL Injection
|
CVE-2008-1982
|
2017-09-29 10:30 |
2008-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259409
|
- |
|
123flashchat e107
|
123_flash_chat_module e107
|
PHP remote file inclusion vulnerability in 123flashchat.php in the 123 Flash Chat 6.8.0 module for e107, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a …
|
CWE-94
Code Injection
|
CVE-2008-1989
|
2017-09-29 10:30 |
2008-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259410
|
- |
|
qemu
|
qemu
|
The drive_init function in QEMU 0.9.1 determines the format of a raw disk image based on the header, which allows local guest users to read arbitrary files on the host by modifying the header to iden…
|
CWE-200
Information Exposure
|
CVE-2008-2004
|
2017-09-29 10:30 |
2008-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|