257021
|
- |
|
comsenz
|
discuz
|
SQL injection vulnerability in index.php in Discuz! 6.0.1 allows remote attackers to execute arbitrary SQL commands via the searchid parameter in a search action.
|
CWE-89
SQL Injection
|
CVE-2008-3554
|
2017-09-29 10:31 |
2008-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257022
|
- |
|
wsn
|
forum gallery knowledge_base links
|
Directory traversal vulnerability in index.php in (1) WSN Forum 4.1.43 and earlier, (2) Gallery 4.1.30 and earlier, (3) Knowledge Base (WSNKB) 4.1.36 and earlier, (4) Links 4.1.44 and earlier, and po…
|
CWE-22
Path Traversal
|
CVE-2008-3555
|
2017-09-29 10:31 |
2008-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257023
|
- |
|
fhm-script
|
free_hosting_manager
|
Free Hosting Manager 1.2 and 2.0 allows remote attackers to bypass authentication and gain administrative access by setting both the adminuser and loggedin cookies.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-3557
|
2017-09-29 10:31 |
2008-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257024
|
- |
|
cisco
|
webex_meeting_manager
|
Stack-based buffer overflow in the WebexUCFObject ActiveX control in atucfobj.dll in Cisco WebEx Meeting Manager before 20.2008.2606.4919 allows remote attackers to execute arbitrary code via a long …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2008-3558
|
2017-09-29 10:31 |
2008-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257025
|
- |
|
dayfox_designs
|
dayfox_blog
|
Multiple directory traversal vulnerabilities in index.php in Dayfox Blog 4 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) p, (2) cat, and (3) archiv…
|
CWE-22
Path Traversal
|
CVE-2008-3564
|
2017-09-29 10:31 |
2008-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257026
|
- |
|
nullsoft
|
winamp
|
Cross-zone scripting vulnerability in the NowPlaying functionality in NullSoft Winamp before 5.541 allows remote attackers to conduct cross-site scripting (XSS) attacks via an MP3 file with JavaScrip…
|
CWE-79
Cross-site Scripting
|
CVE-2008-3567
|
2017-09-29 10:31 |
2008-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257027
|
- |
|
africabegone
|
africa_be_gone
|
PHP remote file inclusion vulnerability in index.php in Africa Be Gone (ABG) 1.0a allows remote attackers to execute arbitrary PHP code via a URL in the abg_path parameter.
|
CWE-94
Code Injection
|
CVE-2008-3570
|
2017-09-29 10:31 |
2008-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257028
|
- |
|
xerox
|
phaser
|
The Xerox Phaser 8400 allows remote attackers to cause a denial of service (reboot) via an empty UDP packet to port 1900.
|
CWE-20
Improper Input Validation
|
CVE-2008-3571
|
2017-09-29 10:31 |
2008-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257029
|
- |
|
hydrairc
|
hydrairc
|
HydraIRC 0.3.164 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a long irc:// URI.
|
CWE-20
Improper Input Validation
|
CVE-2008-3578
|
2017-09-29 10:31 |
2008-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257030
|
- |
|
qsoft
|
k-links
|
Multiple SQL injection vulnerabilities in Qsoft K-Links allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to visit.php, or the PATH_INFO to the default URI under (2) r…
|
CWE-89
SQL Injection
|
CVE-2008-3580
|
2017-09-29 10:31 |
2008-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|