257051
|
- |
|
articlefriendly
|
article_friendly
|
SQL injection vulnerability in authordetail.php in Article Friendly Pro allows remote attackers to execute arbitrary SQL commands via the autid parameter.
|
CWE-89
SQL Injection
|
CVE-2008-3670
|
2017-09-29 10:31 |
2008-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257052
|
- |
|
pozscripts
|
classified_ads
|
SQL injection vulnerability in browsecats.php in PozScripts Classified Ads allows remote attackers to execute arbitrary SQL commands via the cid parameter, a different vector than CVE-2008-3672.
|
CWE-89
SQL Injection
|
CVE-2008-3673
|
2017-09-29 10:31 |
2008-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257053
|
- |
|
pozscripts
|
tubeguru_video_sharing_script
|
SQL injection vulnerability in ugroups.php in PozScripts TubeGuru Video Sharing Script allows remote attackers to execute arbitrary SQL commands via the UID parameter.
|
CWE-89
SQL Injection
|
CVE-2008-3674
|
2017-09-29 10:31 |
2008-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257054
|
- |
|
gelatocms
|
gelatocms
|
Directory traversal vulnerability in classes/imgsize.php in Gelato 0.95 allows remote attackers to read arbitrary files via (1) a .. (dot dot) and possibly (2) a full pathname in the img parameter. …
|
CWE-22
Path Traversal
|
CVE-2008-3675
|
2017-09-29 10:31 |
2008-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257055
|
- |
|
joomla
|
com_user
|
components/com_user/models/reset.php in Joomla! 1.5 through 1.5.5 does not properly validate reset tokens, which allows remote attackers to reset the "first enabled user (lowest id)" password, typica…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-3681
|
2017-09-29 10:31 |
2008-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257056
|
- |
|
jcomsoft speedbit
|
anigif download_accelerator_plus
|
Multiple stack-based buffer overflows in the Animation GIF ActiveX control in JComSoft AniGIF.ocx 1.12 and 2.47, as used in products such as SpeedBit Download Accelerator Plus (DAP) 8.6, allow remote…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2008-3702
|
2017-09-29 10:31 |
2008-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257057
|
- |
|
zeeways
|
zeejobsite
|
SQL injection vulnerability in bannerclick.php in ZEEJOBSITE 2.0 allows remote attackers to execute arbitrary SQL commands via the adid parameter.
|
CWE-89
SQL Injection
|
CVE-2008-3706
|
2017-09-29 10:31 |
2008-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257058
|
- |
|
dotcms
|
dotcms
|
Multiple directory traversal vulnerabilities in dotCMS 1.6.0.9 allow remote attackers to read arbitrary files via a .. (dot dot) in the id parameter to (1) news/index.dot and (2) getting_started/macr…
|
CWE-22
Path Traversal
|
CVE-2008-3708
|
2017-09-29 10:31 |
2008-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257059
|
- |
|
dotcms
|
dotcms
|
In order to exploit this vulnerability to execute arbitrary code, the attacker would first be required to upload a malicious file or inject arbitrary commands into an existing file.
|
CWE-22
Path Traversal
|
CVE-2008-3708
|
2017-09-29 10:31 |
2008-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257060
|
- |
|
phparcadescript
|
phparcadescript
|
SQL injection vulnerability in index.php in PHPArcadeScript (PHP Arcade Script) 4.0 allows remote attackers to execute arbitrary SQL commands via the cat parameter in a browse action.
|
CWE-89
SQL Injection
|
CVE-2008-3711
|
2017-09-29 10:31 |
2008-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|