257131
|
- |
|
advanced_software_engineering
|
chartdirector
|
phpdemo/viewsource.php in Advanced Software Engineering ChartDirector 4.1 allows remote attackers to read sensitive files via the file parameter.
|
CWE-200
Information Exposure
|
CVE-2008-1782
|
2017-09-29 10:30 |
2008-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257132
|
- |
|
prozilla
|
reviews
|
Prozilla Reviews 1.0 allows remote attackers to delete arbitrary users via a modified UserID parameter in a direct request to siteadmin/DeleteUser.php.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-1783
|
2017-09-29 10:30 |
2008-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257133
|
- |
|
prozilla
|
topsites
|
Prozilla Topsites 1.0 allows remote attackers to perform administrative actions via a direct request to (1) addu.php, (2) editu.php, and (3) uidx.php in siteadmin/.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-1784
|
2017-09-29 10:30 |
2008-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257134
|
- |
|
prozilla
|
top_100
|
delete.php in Prozilla Top 100 1.2 allows remote authenticated users to delete statistics and accounts of arbitrary users via a modified s parameter.
|
CWE-20
Improper Input Validation
|
CVE-2008-1785
|
2017-09-29 10:30 |
2008-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257135
|
- |
|
prozilla
|
forum
|
SQL injection vulnerability in forum.php in Prozilla Forum allows remote attackers to execute arbitrary SQL commands via the forum parameter.
|
CWE-89
SQL Injection
|
CVE-2008-1789
|
2017-09-29 10:30 |
2008-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257136
|
- |
|
iscripts
|
socialware
|
Unrestricted file upload vulnerability in iScripts SocialWare allows remote authenticated administrators to upload arbitrary files via a crafted logo file in the "Manage Settings" functionality. NOT…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-1790
|
2017-09-29 10:30 |
2008-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257137
|
- |
|
mygamingladder
|
mygamingladder
|
SQL injection vulnerability in ladder.php in My Gaming Ladder 7.5 and earlier allows remote attackers to execute arbitrary SQL commands via the ladderid parameter.
|
CWE-89
SQL Injection
|
CVE-2008-1791
|
2017-09-29 10:30 |
2008-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257138
|
- |
|
dragoon
|
dragoon
|
Directory traversal vulnerability in forum/kietu/libs/calendrier.php in Dragoon 0.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the cal[lng] parameter.
|
CWE-22
Path Traversal
|
CVE-2008-1798
|
2017-09-29 10:30 |
2008-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257139
|
- |
|
sabros.us
|
sabros.us
|
Directory traversal vulnerability in thumbnails.php in sabros.us 1.75 allows remote attackers to read arbitrary files via a .. (dot dot) in the img parameter.
|
CWE-22
Path Traversal
|
CVE-2008-1799
|
2017-09-29 10:30 |
2008-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257140
|
- |
|
rdesktop
|
rdesktop
|
Integer underflow in the iso_recv_msg function (iso.c) in rdesktop 1.5.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a Remote Desktop Protocol…
|
CWE-189
Numeric Errors
|
CVE-2008-1801
|
2017-09-29 10:30 |
2008-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|