256721
|
- |
|
bearrivernet.net
|
i-pos_internet_pay_online_store
|
SQL injection vulnerability in index.asp in I-Pos Internet Pay Online Store 1.3 Beta and earlier allows remote attackers to execute arbitrary SQL commands via the item parameter.
|
CWE-89
SQL Injection
|
CVE-2008-2634
|
2017-09-29 10:31 |
2008-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256722
|
- |
|
1-script
|
1-book
|
Static code injection vulnerability in guestbook.php in 1Book 1.0.1 and earlier allows remote attackers to upload arbitrary PHP code via the message parameter in an HTML webform, which is written to …
|
CWE-94
Code Injection
|
CVE-2008-2638
|
2017-09-29 10:31 |
2008-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256723
|
- |
|
joomla
|
com_biblestudy
|
SQL injection vulnerability in the Bible Study (com_biblestudy) component before 6.0.7c for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a mediaplayer act…
|
CWE-89
SQL Injection
|
CVE-2008-2643
|
2017-09-29 10:31 |
2008-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256724
|
- |
|
brim-project
|
brim
|
Multiple PHP remote file inclusion vulnerabilities in Brim (formerly Booby) 1.0.1 allow remote attackers to execute arbitrary PHP code via a URL in the renderer parameter to template.tpl.php in (1) b…
|
CWE-94
Code Injection
|
CVE-2008-2645
|
2017-09-29 10:31 |
2008-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256725
|
- |
|
mebiblio
|
mebiblio
|
Multiple cross-site scripting (XSS) vulnerabilities in meBiblio 0.4.7 allow remote attackers to inject arbitrary web script or HTML via the (1) sql parameter to dbadd.inc.php, (2) InsertJournal param…
|
CWE-79
Cross-site Scripting
|
CVE-2008-2646
|
2017-09-29 10:31 |
2008-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256726
|
- |
|
mebiblio
|
mebiblio
|
SQL injection vulnerability in admin/journal_change_mask.inc.php in meBiblio 0.4.7 allows remote attackers to execute arbitrary SQL commands via the JID parameter.
|
CWE-89
SQL Injection
|
CVE-2008-2647
|
2017-09-29 10:31 |
2008-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256727
|
- |
|
mebiblio
|
mebiblio
|
Unrestricted file upload vulnerability in upload/uploader.html in meBiblio 0.4.7 allows remote attackers to execute arbitrary code by uploading a .php file, then accessing it via a direct request to …
|
CWE-20
Improper Input Validation
|
CVE-2008-2648
|
2017-09-29 10:31 |
2008-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256728
|
- |
|
don3
|
desktoponnet
|
Multiple PHP remote file inclusion vulnerabilities in DesktopOnNet 3 Beta allow remote attackers to execute arbitrary PHP code via a URL in the app_path parameter to (1) don3_requiem.don3app/don3_req…
|
CWE-94
Code Injection
|
CVE-2008-2649
|
2017-09-29 10:31 |
2008-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256729
|
- |
|
cmsimple
|
cmsimple
|
Directory traversal vulnerability in cmsimple/cms.php in CMSimple 3.1, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the…
|
CWE-22
Path Traversal
|
CVE-2008-2650
|
2017-09-29 10:31 |
2008-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256730
|
- |
|
cmsimple
|
cmsimple
|
Upgrade requires login when downloads link is clicked from X-Force site.
|
CWE-22
Path Traversal
|
CVE-2008-2650
|
2017-09-29 10:31 |
2008-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|