256821
|
- |
|
mambo
|
mambo
|
PHP remote file inclusion vulnerability in includes/Cache/Lite/Output.php in the Cache_Lite package in Mambo 4.6.4 and earlier, when register_globals is enabled, allows remote attackers to execute ar…
|
CWE-94
Code Injection
|
CVE-2008-2905
|
2017-09-29 10:31 |
2008-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256822
|
- |
|
webchamado
|
webchamado
|
SQL injection vulnerability in lista_anexos.php in WebChamado 1.1 allows remote attackers to execute arbitrary SQL commands via the tsk_id parameter.
|
CWE-89
SQL Injection
|
CVE-2008-2906
|
2017-09-29 10:31 |
2008-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256823
|
- |
|
webchamado
|
webchamado
|
SQL injection vulnerability in admin/index.php in WebChamado 1.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the eml parameter.
|
CWE-89
SQL Injection
|
CVE-2008-2907
|
2017-09-29 10:31 |
2008-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256824
|
- |
|
muvee
|
autoproducer
|
Buffer overflow in the DXTTextOutEffect ActiveX control (aka the Text-Effect DXT Filter), as distributed in TextOut.dll 6.0.18.1 and mvtextout.dll, in muvee autoProducer 6.0 and 6.1 allows remote att…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2008-2910
|
2017-09-29 10:31 |
2008-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256825
|
- |
|
contenido
|
contendio
|
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Contenido 4.8.4 allow remote attackers to inject arbitrary web script or HTML via the (1) contenido, (2) Belang, and (3) username p…
|
CWE-79
Cross-site Scripting
|
CVE-2008-2911
|
2017-09-29 10:31 |
2008-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256826
|
- |
|
contenido
|
contenido_cms
|
Multiple PHP remote file inclusion vulnerabilities in Contenido CMS 4.8.4 allow remote attackers to execute arbitrary PHP code via a URL in the (1) contenido_path parameter to (a) contenido/backend_s…
|
CWE-94
Code Injection
|
CVE-2008-2912
|
2017-09-29 10:31 |
2008-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256827
|
- |
|
devalcms
|
devalcms
|
Directory traversal vulnerability in func.php in Devalcms 1.4a, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the curre…
|
CWE-22
Path Traversal
|
CVE-2008-2913
|
2017-09-29 10:31 |
2008-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256828
|
- |
|
preprojects
|
pre_job_board
|
Multiple SQL injection vulnerabilities in jobseekers/JobSearch.php (aka the search module) in Pre Job Board allow remote attackers to execute arbitrary SQL commands via the (1) position or (2) kw par…
|
CWE-89
SQL Injection
|
CVE-2008-2915
|
2017-09-29 10:31 |
2008-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256829
|
- |
|
application_dynamics
|
cartweaver
|
SQL injection vulnerability in details.php in Application Dynamics Cartweaver 3.0 allows remote attackers to execute arbitrary SQL commands via the prodId parameter, possibly a related issue to CVE-2…
|
CWE-89
SQL Injection
|
CVE-2008-2918
|
2017-09-29 10:31 |
2008-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256830
|
- |
|
gryphonllc
|
gryphon_gllcts2
|
SQL injection vulnerability in listing.php in Gryphon gllcTS2 4.2.4 allows remote attackers to execute arbitrary SQL commands via the sort parameter.
|
CWE-89
SQL Injection
|
CVE-2008-2919
|
2017-09-29 10:31 |
2008-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|