256371
|
- |
|
china-on-site
|
flexphplink
|
Unrestricted file upload vulnerability in submitlink.php in FlexPHPLink Pro 0.0.7 allows remote attackers to execute arbitrary PHP code by uploading a file with an executable extension, then accessin…
|
CWE-20
Improper Input Validation
|
CVE-2008-6731
|
2017-09-29 10:33 |
2009-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256372
|
- |
|
keller_web_admin
|
kwa
|
Directory traversal vulnerability in Public/index.php in Keller Web Admin CMS 0.94 Pro allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the action parameter.
|
CWE-22
Path Traversal
|
CVE-2008-6734
|
2017-09-29 10:33 |
2009-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256373
|
- |
|
thaiquickcart
|
thaiquickcart
|
Directory traversal vulnerability in qc/index.php in ThaiQuickCart 3 allows remote attackers to read arbitrary files via a .. (dot dot) in the sLanguage cookie.
|
CWE-22
Path Traversal
|
CVE-2008-6735
|
2017-09-29 10:33 |
2009-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256374
|
- |
|
mark_girling
|
myshoutpro
|
MyShoutPro 1.2 allows remote attackers to bypass authentication and gain administrative access by setting the admin_access cookie to 1.
|
CWE-287
Improper Authentication
|
CVE-2008-6738
|
2017-09-29 10:33 |
2009-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256375
|
- |
|
toddwoolums
|
asp_download
|
Todd Woolums ASP Download management script 1.03 does not require authentication for setupdownload.asp, which allows remote attackers to gain administrator privileges via a direct request.
|
CWE-287
Improper Authentication
|
CVE-2008-6739
|
2017-09-29 10:33 |
2009-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256376
|
- |
|
homap
|
homap
|
PHP remote file inclusion vulnerability in html/admin/modules/plugin_admin.php in HoMaP-CMS 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the _settings[pluginpath] parameter.
|
CWE-94
Code Injection
|
CVE-2008-6740
|
2017-09-29 10:33 |
2009-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256377
|
- |
|
simple_machines
|
simple_machines_forum
|
SQL injection vulnerability in Load.php in Simple Machines Forum (SMF) 1.1.4 and earlier allows remote attackers to execute arbitrary SQL commands by setting the db_character_set parameter to a multi…
|
CWE-89
SQL Injection
|
CVE-2008-6741
|
2017-09-29 10:33 |
2009-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256378
|
- |
|
gofoxy
|
foxy
|
Foxy P2P software allows remote attackers to cause a denial of service (memory consumption) via a foxy URI with a download action and a large fs value.
|
CWE-20
Improper Input Validation
|
CVE-2008-6742
|
2017-09-29 10:33 |
2009-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256379
|
- |
|
shock-therapy
|
rsmscript
|
RSMScript 1.21 allows remote attackers to bypass authentication and gain administrative privileges by setting the verified cookie to an arbitrary value and performing a direct request to (1) delete.p…
|
CWE-287
Improper Authentication
|
CVE-2008-6743
|
2017-09-29 10:33 |
2009-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256380
|
- |
|
blogphp
|
blogphp
|
index.php in BlogPHP 2.0 allows remote attackers to gain administrator privileges via a crafted email parameter in a register2 action.
|
CWE-20
Improper Input Validation
|
CVE-2008-6745
|
2017-09-29 10:33 |
2009-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|