256611
|
- |
|
igamingcms
|
igaming_cms
|
Multiple SQL injection vulnerabilities in iGaming 1.5 and earlier allow remote attackers to execute arbitrary SQL commands via the browse parameter to (1) previews.php and (2) reviews.php, and the (3…
|
CWE-89
SQL Injection
|
CVE-2008-5841
|
2017-09-29 10:32 |
2009-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256612
|
- |
|
constructr
|
constructr-cms
|
Constructr CMS 3.02.5 and earlier stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain sensitive information by reading the hash column.
|
CWE-255
Credentials Management
|
CVE-2008-5847
|
2017-09-29 10:32 |
2009-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256613
|
- |
|
mypbs
|
mypbs
|
SQL injection vulnerability in index.php in My PHP Baseball Stats (MyPBS) allows remote attackers to execute arbitrary SQL commands via the seasonID parameter.
|
CWE-89
SQL Injection
|
CVE-2008-5851
|
2017-09-29 10:32 |
2009-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256614
|
- |
|
emefa
|
emefa_guestbook
|
Emefa Guestbook 3.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for guestbook.md…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-5852
|
2017-09-29 10:32 |
2009-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256615
|
- |
|
myphpscripts
|
login_session
|
Multiple cross-site scripting (XSS) vulnerabilities in login.php in myPHPscripts Login Session 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) ls_user and (2) ls_email p…
|
CWE-79
Cross-site Scripting
|
CVE-2008-5854
|
2017-09-29 10:32 |
2009-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256616
|
- |
|
myphpscripts
|
login_session
|
myPHPscripts Login Session 2.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to discover usernames, e-mail addresses, and password ha…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-5855
|
2017-09-29 10:32 |
2009-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256617
|
- |
|
class
|
class
|
Directory traversal vulnerability in scripts/export.php in ClaSS before 0.8.61 allows remote attackers to read arbitrary files via directory traversal sequences in the ftype parameter.
|
CWE-22
Path Traversal
|
CVE-2008-5856
|
2017-09-29 10:32 |
2009-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256618
|
- |
|
constructr
|
constructr-cms
|
SQL injection vulnerability in index.php in Constructr CMS 3.02.5 and earlier, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL comm…
|
CWE-89
SQL Injection
|
CVE-2008-5859
|
2017-09-29 10:32 |
2009-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256619
|
- |
|
constructr
|
constructr-cms
|
Directory traversal vulnerability in backend/template.php in Constructr CMS 3.02.5 and earlier, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to create or…
|
CWE-22
Path Traversal
|
CVE-2008-5860
|
2017-09-29 10:32 |
2009-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256620
|
- |
|
freelyrics
|
freelyrics
|
Directory traversal vulnerability in source.php in FreeLyrics 1.0 allows remote attackers to read arbitrary files via directory traversal sequences in the p parameter. NOTE: some of these details ar…
|
CWE-22
Path Traversal
|
CVE-2008-5861
|
2017-09-29 10:32 |
2009-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|