256611
|
- |
|
injader
|
injader
|
SQL injection vulnerability in feeds.php in Injader before 2.1.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2008-5890
|
2017-09-29 10:32 |
2009-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256612
|
- |
|
icash
|
click\&email
|
Multiple SQL injection vulnerabilities in ClickAndEmail allow remote attackers to execute arbitrary SQL commands via (1) the ID parameter to admin_dblayers.asp in an update action, (2) the adminid pa…
|
CWE-89
SQL Injection
|
CVE-2008-5892
|
2017-09-29 10:32 |
2009-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256613
|
- |
|
icash
|
click\&email
|
Cross-site scripting (XSS) vulnerability in admin_dblayers.asp in ClickAndEmail allows remote attackers to inject arbitrary web script or HTML via the tablename parameter in an update action.
|
CWE-79
Cross-site Scripting
|
CVE-2008-5893
|
2017-09-29 10:32 |
2009-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256614
|
- |
|
mediatheka
|
mediatheka
|
Directory traversal vulnerability in index.php in Mediatheka 4.2 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter.
|
CWE-22
Path Traversal
|
CVE-2008-5894
|
2017-09-29 10:32 |
2009-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256615
|
- |
|
mediatheka
|
mediatheka
|
SQL injection vulnerability in connection.php in Mediatheka 4.2 and earlier allows remote attackers to execute arbitrary SQL commands via the user parameter.
|
CWE-89
SQL Injection
|
CVE-2008-5895
|
2017-09-29 10:32 |
2009-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256616
|
- |
|
codeavalanche
|
ratemysite
|
CodeAvalanche RateMySite stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing the administrator pas…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-5896
|
2017-09-29 10:32 |
2009-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256617
|
- |
|
codeavalanche
|
freewallpaper
|
CodeAvalanche FreeWallpaper stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing the administrator …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-5897
|
2017-09-29 10:32 |
2009-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256618
|
- |
|
codeavalanche
|
directory
|
CodeAvalanche Directory stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing the administrator pass…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-5898
|
2017-09-29 10:32 |
2009-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256619
|
- |
|
codeavalanche
|
freeforall
|
CodeAvalanche FreeForAll stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing the administrator pas…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-5899
|
2017-09-29 10:32 |
2009-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256620
|
- |
|
codeavalanche
|
articles
|
CodeAvalanche Articles stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing the administrator passw…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-5900
|
2017-09-29 10:32 |
2009-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|