257161
|
- |
|
spacial_audio_solutions
|
sam_broadcaster samphpweb
|
PHP remote file inclusion vulnerability in common/db.php in samPHPweb, possibly 4.2.2 and others, as provided with SAM Broadcaster, allows remote attackers to execute arbitrary PHP code via a URL in …
|
CWE-94
Code Injection
|
CVE-2008-0143
|
2017-09-29 10:30 |
2008-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257162
|
- |
|
phprisk
|
netrisk
|
PHP remote file inclusion vulnerability in index.php in NetRisk 1.9.7 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the page parameter. NOTE: this can also be levera…
|
CWE-89
SQL Injection
|
CVE-2008-0144
|
2017-09-29 10:30 |
2008-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257163
|
- |
|
smallnuke
|
smallnuke
|
SQL injection vulnerability in index.php in SmallNuke 2.0.4 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via (1) the user_email parameter …
|
CWE-89
SQL Injection
|
CVE-2008-0147
|
2017-09-29 10:30 |
2008-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257164
|
- |
|
evilboard
|
evilboard
|
SQL injection vulnerability in index.php in EvilBoard 0.1a (Alpha) allows remote attackers to execute arbitrary SQL commands the c parameter.
|
CWE-89
SQL Injection
|
CVE-2008-0154
|
2017-09-29 10:30 |
2008-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257165
|
- |
|
evilboard
|
evilboard
|
Cross-site scripting (XSS) vulnerability in index.php in EvilBoard 0.1a (Alpha) allows remote attackers to inject arbitrary web script or HTML via the c parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2008-0155
|
2017-09-29 10:30 |
2008-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257166
|
- |
|
flexbb
|
flexbb
|
SQL injection vulnerability in FlexBB 0.6.3 and earlier allows remote attackers to execute arbitrary SQL commands via the flexbb_temp_id parameter in a cookie.
|
CWE-89
SQL Injection
|
CVE-2008-0157
|
2017-09-29 10:30 |
2008-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257167
|
- |
|
shop-script
|
shop-script
|
Directory traversal vulnerability in index.php in Shop-Script 2.0 and possibly other versions allows remote attackers to read arbitrary files via a .. (dot dot) in the aux_page parameter.
|
CWE-22
Path Traversal
|
CVE-2008-0158
|
2017-09-29 10:30 |
2008-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257168
|
- |
|
eggblog
|
eggblog
|
SQL injection vulnerability in index.php in eggBlog 3.1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the eggblogpassword parameter in a cookie.
|
CWE-89
SQL Injection
|
CVE-2008-0159
|
2017-09-29 10:30 |
2008-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257169
|
- |
|
spacial_audio_solutions
|
samphpweb
|
SQL injection vulnerability in songinfo.php in SAM Broadcaster samPHPweb, possibly 4.2.2 and earlier, allows remote attackers to execute arbitrary SQL commands via the songid parameter.
|
CWE-89
SQL Injection
|
CVE-2008-0187
|
2017-09-29 10:30 |
2008-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257170
|
- |
|
uebimiau
|
webmail
|
Uebimiau Webmail 2.7.10 and 2.7.2 does not protect authentication state variables from being set through HTTP requests, which allows remote attackers to bypass authentication via a sess[auth]=1 param…
|
CWE-287
Improper Authentication
|
CVE-2008-0210
|
2017-09-29 10:30 |
2008-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|