261241
|
- |
|
hisanaga_electric_co
|
hisa_cart
|
Unspecified vulnerability in Hisanaga Electric Co, Ltd. hisa_cart 1.29 and earlier, a module for XOOPS, allows remote attackers to obtain sensitive user information via unknown vectors.
|
CWE-200
Information Exposure
|
CVE-2008-4635
|
2017-08-8 10:32 |
2008-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261242
|
- |
|
cpcommerce
|
cpcommerce
|
Cross-site scripting (XSS) vulnerability in cpCommerce before 1.2.4 allows remote attackers to inject arbitrary web script or HTML via unknown vectors in the advanced search feature. NOTE: this is p…
|
CWE-79
Cross-site Scripting
|
CVE-2008-4637
|
2017-08-8 10:32 |
2008-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261243
|
- |
|
cpcommerce
|
cpcommerce
|
Patch Information: http://cpcommerce.cpradio.org/downloads.php
|
CWE-79
Cross-site Scripting
|
CVE-2008-4637
|
2017-08-8 10:32 |
2008-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261244
|
- |
|
sweetcms
|
sweetcms
|
SQL injection vulnerability in index.php in sweetCMS 1.5.2 allows remote attackers to execute arbitrary SQL commands via the page parameter.
|
CWE-89
SQL Injection
|
CVE-2008-4647
|
2017-08-8 10:32 |
2008-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261245
|
- |
|
elxis
|
elxis_cms
|
Cross-site scripting (XSS) vulnerability in index.php in Elxis CMS 2008.1 revision 2204 allows remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO or the (2) option, (3) Ite…
|
CWE-79
Cross-site Scripting
|
CVE-2008-4648
|
2017-08-8 10:32 |
2008-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261246
|
- |
|
elxis
|
elxis_cms
|
Session fixation vulnerability in Elxis CMS 2008.1 revision 2204 allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.
|
CWE-287
Improper Authentication
|
CVE-2008-4649
|
2017-08-8 10:32 |
2008-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261247
|
- |
|
jetbox
|
jetbox_cms
|
Multiple SQL injection vulnerabilities in Jetbox CMS 2.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) orderby parameter to admin/cms/images.php and the (2) nav_id pa…
|
CWE-89
SQL Injection
|
CVE-2008-4651
|
2017-08-8 10:32 |
2008-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261248
|
- |
|
typo3
|
m1_intern
|
SQL injection vulnerability in the M1 Intern (m1_intern) 1.0.0 extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
|
CWE-89
SQL Injection
|
CVE-2008-4660
|
2017-08-8 10:32 |
2008-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261249
|
- |
|
kumacchi
|
ks_cgi_access_log
|
Cross-site scripting (XSS) vulnerability in analysis.cgi 1.44, as used in K's CGI Access Log Kaiseki (1) jcode.pl and (2) Jcode.pm, allows remote attackers to inject arbitrary web script or HTML via …
|
CWE-79
Cross-site Scripting
|
CVE-2008-4663
|
2017-08-8 10:32 |
2008-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261250
|
- |
|
qvod
|
qvod_player
|
Heap-based buffer overflow in QvodInsert.QvodCtrl.1 ActiveX control (QvodInsert.dll) in QVOD Player before 2.1.5 build 0053 allows remote attackers to execute arbitrary code via a long URL property. …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2008-4664
|
2017-08-8 10:32 |
2008-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|