256601
|
- |
|
phpclanwebsite
|
phpclanwebsite
|
Multiple SQL injection vulnerabilities in Phpclanwebsite (aka PCW) 1.23.3 Fix Pack 5 and earlier, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (…
|
CWE-89
SQL Injection
|
CVE-2008-5877
|
2017-09-29 10:32 |
2009-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256602
|
- |
|
phpclanwebsite
|
phpclanwebsite
|
Multiple directory traversal vulnerabilities in Phpclanwebsite (aka PCW) 1.23.3 Fix Pack 5 and earlier, when magic_quotes_gpc is disabled and register_globals is enabled, allow remote attackers to in…
|
CWE-22
Path Traversal
|
CVE-2008-5878
|
2017-09-29 10:32 |
2009-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256603
|
- |
|
phpclanwebsite
|
phpclanwebsite
|
Cross-site scripting (XSS) vulnerability in index.php in Phpclanwebsite (aka PCW) 1.23.3 Fix Pack 5 and earlier, allows remote attackers to inject arbitrary web script or HTML via the page parameter …
|
CWE-79
Cross-site Scripting
|
CVE-2008-5879
|
2017-09-29 10:32 |
2009-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256604
|
- |
|
gobbl
|
gobbl_cms
|
admin/auth.php in Gobbl CMS 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the auth cookie to "ok".
|
CWE-287
Improper Authentication
|
CVE-2008-5880
|
2017-09-29 10:32 |
2009-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256605
|
- |
|
playsms
|
playsms
|
Multiple directory traversal vulnerabilities in playSMS 0.9.3 allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the (1) gateway_module parameter…
|
CWE-22
Path Traversal
|
CVE-2008-5881
|
2017-09-29 10:32 |
2009-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256606
|
- |
|
mini-pub
|
mini-pub
|
Absolute path traversal vulnerability in front-end/dir.php in mini-pub 0.3 and earlier allows remote attackers to list arbitrary directories via a full pathname in the sDir parameter.
|
CWE-22
Path Traversal
|
CVE-2008-5883
|
2017-09-29 10:32 |
2009-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256607
|
- |
|
thenetguys
|
aspired2quote
|
The Net Guys ASPired2Quote stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing usernames and passw…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-5885
|
2017-09-29 10:32 |
2009-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256608
|
- |
|
takempis
|
discussion_web
|
TAKempis Discussion Web 4.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing a password via a d…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-5886
|
2017-09-29 10:32 |
2009-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256609
|
- |
|
icash
|
click\&rank
|
Multiple SQL injection vulnerabilities in Click&Rank allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) hitcounter.asp, (2) user_delete.asp, and (3) user_update.asp;…
|
CWE-89
SQL Injection
|
CVE-2008-5888
|
2017-09-29 10:32 |
2009-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256610
|
- |
|
icash
|
click\&rank
|
Cross-site scripting (XSS) vulnerability in user.asp in Click&Rank allows remote attackers to inject arbitrary web script or HTML via the action parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2008-5889
|
2017-09-29 10:32 |
2009-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|