259691
|
- |
|
fascript
|
faphoto
|
SQL injection vulnerability in show.php in FaScript FaPhoto 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2008-1714
|
2017-09-29 10:30 |
2008-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259692
|
- |
|
auracms
|
auracms
|
SQL injection vulnerability in content/user.php in AuraCMS 2.2.1 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the country parameter.
|
CWE-89
SQL Injection
|
CVE-2008-1715
|
2017-09-29 10:30 |
2008-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259693
|
- |
|
nsoftware
|
ibiz_e-banking_integrator
|
The IBizEBank.FIProfile.1 ActiveX control in fiprofile20.ocx in IBiz E-Banking Integrator (formerly IBiz OFX Integrator) 2.0.2932 exposes the unsafe WriteOFXDataFile method, which allows remote attac…
|
NVD-CWE-Other
|
CVE-2008-1725
|
2017-09-29 10:30 |
2008-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259694
|
- |
|
myknowledgequest
|
knowledgequest
|
Multiple SQL injection vulnerabilities in KnowledgeQuest 2.6, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) kqid parameter to (a) articletext…
|
CWE-89
SQL Injection
|
CVE-2008-1726
|
2017-09-29 10:30 |
2008-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259695
|
- |
|
myknowledgequest
|
knowledgequest
|
KnowledgeQuest 2.5 and 2.6 does not require authentication for access to admincheck.php, which allows remote attackers to create arbitrary admin accounts.
|
CWE-287
Improper Authentication
|
CVE-2008-1727
|
2017-09-29 10:30 |
2008-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259696
|
- |
|
predictionfootball
|
predictionfootball
|
SQL injection vulnerability in showpredictionsformatch.php in Prediction Football 1.x allows remote attackers to execute arbitrary SQL commands via the matchid parameter in a dupa action.
|
CWE-89
SQL Injection
|
CVE-2008-1732
|
2017-09-29 10:30 |
2008-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259697
|
- |
|
livecart
|
livecart
|
SQL injection vulnerability in Integry Systems LiveCart 1.1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter to the /category URI.
|
CWE-89
SQL Injection
|
CVE-2008-1750
|
2017-09-29 10:30 |
2008-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259698
|
- |
|
ksemail
|
ksemail
|
Multiple directory traversal vulnerabilities in index.php in Ksemail allow remote attackers to read arbitrary local files via a .. (dot dot) in the (1) language and (2) lang parameters.
|
CWE-22
Path Traversal
|
CVE-2008-1751
|
2017-09-29 10:30 |
2008-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259699
|
- |
|
zekewalker
|
world_of_phaos
|
Directory traversal vulnerability in the showSource function in showSource.php in World of Phaos 4.0.1 allows remote attackers to read arbitrary files via directory traversal sequences in the file pa…
|
CWE-22
Path Traversal
|
CVE-2008-1755
|
2017-09-29 10:30 |
2008-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259700
|
- |
|
kwsphp
|
kwsphp
|
SQL injection vulnerability in the ConcoursPhoto module for KwsPHP allows remote attackers to execute arbitrary SQL commands via the C_ID parameter to index.php.
|
CWE-89
SQL Injection
|
CVE-2008-1758
|
2017-09-29 10:30 |
2008-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|