256701
|
- |
|
deluxebb
|
deluxebb
|
SQL injection vulnerability in forums.php in DeluxeBB 1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the sort parameter.
|
CWE-89
SQL Injection
|
CVE-2008-2194
|
2017-09-29 10:31 |
2008-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256702
|
- |
|
deluxebb
|
deluxebb
|
Static code injection vulnerability in admincp.php in DeluxeBB 1.2 and earlier allows remote authenticated administrators to inject arbitrary PHP code into logs/cp.php via the URI.
|
CWE-94
Code Injection
|
CVE-2008-2195
|
2017-09-29 10:31 |
2008-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256703
|
- |
|
miniweb2
|
blog_writer
|
SQL injection vulnerability in the blogwriter module 2.0 for Miniweb allows remote attackers to execute arbitrary SQL commands via the historymonth parameter to index.php.
|
CWE-89
SQL Injection
|
CVE-2008-2197
|
2017-09-29 10:31 |
2008-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256704
|
- |
|
pbcs
|
project-based_calendaring__system
|
Multiple directory traversal vulnerabilities in Project-Based Calendaring System (PBCS) 0.7.1-1 allow remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter to (1) src/…
|
CWE-22
Path Traversal
|
CVE-2008-2215
|
2017-09-29 10:31 |
2008-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256705
|
- |
|
pbcs
|
project-based_calendaring__system
|
Unrestricted file upload vulnerability in src/yopy_upload.php in Project-Based Calendaring System (PBCS) 0.7.1 allows remote authenticated users to upload arbitrary files to tmp/uploads.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-2216
|
2017-09-29 10:31 |
2008-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256706
|
- |
|
mario_valdez
|
content_management_system
|
Directory traversal vulnerability in cm/graphie.php in Content Management System 0.6.1 for Phprojekt allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the cm_…
|
CWE-22
Path Traversal
|
CVE-2008-2217
|
2017-09-29 10:31 |
2008-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256707
|
- |
|
interact
|
interact
|
Multiple PHP remote file inclusion vulnerabilities in Interact Learning Community Environment Interact 2.4.1, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code vi…
|
CWE-94
Code Injection
|
CVE-2008-2220
|
2017-09-29 10:31 |
2008-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256708
|
- |
|
eqdkp
|
eqdkp
|
SQL injection vulnerability in login.php in EQdkp 1.3.2f allows remote attackers to bypass EQdkp user authentication via the user_id parameter.
|
CWE-89
SQL Injection
|
CVE-2008-2222
|
2017-09-29 10:31 |
2008-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256709
|
- |
|
buyscripts
|
vshare_youtube_clone
|
SQL injection vulnerability in group_posts.php in vShare YouTube Clone 2.6 allows remote attackers to execute arbitrary SQL commands via the tid parameter.
|
CWE-89
SQL Injection
|
CVE-2008-2223
|
2017-09-29 10:31 |
2008-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256710
|
- |
|
sazcart
|
sazcart
|
Multiple PHP remote file inclusion vulnerabilities in SazCart 1.5.1, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) _saz[settings][site_di…
|
CWE-94
Code Injection
|
CVE-2008-2224
|
2017-09-29 10:31 |
2008-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|