257471
|
- |
|
netwin
|
surgemail
|
Stack-based buffer overflow in the IMAP service in NetWin Surgemail 3.8k4-4 and earlier allows remote authenticated users to execute arbitrary code via a long first argument to the LIST command.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2008-1498
|
2017-09-29 10:30 |
2008-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257472
|
- |
|
sstreamtv
|
custompages
|
PHP remote file inclusion vulnerability in the SSTREAMTV custompages (com_custompages) 1.1 and earlier component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the cpa…
|
CWE-94
Code Injection
|
CVE-2008-1505
|
2017-09-29 10:30 |
2008-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257473
|
- |
|
peel
|
peel
|
PEEL, possibly 3.x and earlier, allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function.
|
CWE-200
Information Exposure
|
CVE-2008-1506
|
2017-09-29 10:30 |
2008-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257474
|
- |
|
peel
|
peel
|
PEEL, possibly 3.x and earlier, has (1) a default info@peel.fr account with password admin, and (2) a default contact@peel.fr account with password cinema, which allows remote attackers to gain admin…
|
CWE-16
Configuration
|
CVE-2008-1507
|
2017-09-29 10:30 |
2008-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257475
|
- |
|
xlportal
|
xlportal
|
SQL injection vulnerability in index.php in XLPortal 2.2.4 and earlier allows remote attackers to execute arbitrary SQL commands via the query parameter.
|
CWE-89
SQL Injection
|
CVE-2008-1509
|
2017-09-29 10:30 |
2008-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257476
|
- |
|
phpbb
|
module_xs
|
Directory traversal vulnerability in admin/admin_xs.php in eXtreme Styles module (XS-Mod) 2.3.1 and 2.4.0 for phpBB allows remote attackers to include and execute arbitrary files via a .. (dot dot) i…
|
CWE-22
Path Traversal
|
CVE-2008-1512
|
2017-09-29 10:30 |
2008-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257477
|
- |
|
danneo
|
cms
|
SQL injection vulnerability in index.php in Danneo CMS 0.5.1 and earlier, when the Referers statistics option is enabled, allows remote attackers to execute arbitrary SQL commands via the HTTP Refere…
|
CWE-89
SQL Injection
|
CVE-2008-1513
|
2017-09-29 10:30 |
2008-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257478
|
- |
|
matti_kiviharju
|
rekry_component
|
SQL injection vulnerability in the Matti Kiviharju rekry (aka com_rekry or rekry!Joom) 1.0.0 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the op_id parameter in…
|
CWE-89 CWE-20
SQL Injection Improper Input Validation
|
CVE-2008-1535
|
2017-09-29 10:30 |
2008-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257479
|
- |
|
futurenuke
|
php_nuke_platinum
|
SQL injection vulnerability in includes/dynamic_titles.php in PHP-Nuke Platinum 7.6.b.5 allows remote attackers to execute arbitrary SQL commands via the p parameter to modules.php for the Forums mod…
|
CWE-89
SQL Injection
|
CVE-2008-1539
|
2017-09-29 10:30 |
2008-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257480
|
- |
|
topper
|
toppermod
|
Directory traversal vulnerability in mod.php in TopperMod 1.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the to parameter.
|
CWE-22
Path Traversal
|
CVE-2008-1553
|
2017-09-29 10:30 |
2008-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|