256931
|
- |
|
realm_project
|
realm_cms
|
Realm CMS 2.3 and earlier allows remote attackers to obtain sensitive information via a direct request to _db/compact.asp, which reveals the database path in an error message.
|
CWE-200
Information Exposure
|
CVE-2008-2681
|
2017-09-29 10:31 |
2008-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256932
|
- |
|
realm_project
|
realm_cms
|
_RealmAdmin/login.asp in Realm CMS 2.3 and earlier allows remote attackers to bypass authentication and access admin pages via certain modified cookies, probably including (1) cUserRole, (2) cUserNam…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-2682
|
2017-09-29 10:31 |
2008-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256933
|
- |
|
black_ice
|
barcode_sdk
|
The BIDIB.BIDIBCtrl.1 ActiveX control in BIDIB.ocx 10.9.3.0 in Black Ice Barcode SDK 5.01 allows remote attackers to force the download and storage of arbitrary files by specifying the origin URL in …
|
CWE-20
Improper Input Validation
|
CVE-2008-2683
|
2017-09-29 10:31 |
2008-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256934
|
- |
|
blackice
|
black_ice_barcode_sdk
|
The BIDIB.BIDIBCtrl.1 ActiveX control in BIDIB.ocx 10.9.3.0 in Black Ice Barcode SDK 5.01 allows remote attackers to execute arbitrary code via long strings in the two arguments to the DownloadImageF…
|
CWE-94
Code Injection
|
CVE-2008-2684
|
2017-09-29 10:31 |
2008-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256935
|
- |
|
flux_cms
|
flux_cms
|
webinc/bxe/scripts/loadsave.php in Flux CMS 1.5.0 and earlier allows remote attackers to execute arbitrary code by overwriting a PHP file in webinc/bxe/scripts/ via a filename in the XML parameter an…
|
CWE-20
Improper Input Validation
|
CVE-2008-2686
|
2017-09-29 10:31 |
2008-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256936
|
- |
|
promanager
|
promanager
|
Directory traversal vulnerability in inc/config.php in ProManager 0.73 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter.
|
CWE-22
Path Traversal
|
CVE-2008-2687
|
2017-09-29 10:31 |
2008-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256937
|
- |
|
pilotcart
|
pilot_cart
|
SQL injection vulnerability in pilot.asp in ASPilot Pilot Cart 7.3 allows remote attackers to execute arbitrary SQL commands via the article parameter in a kb action.
|
CWE-89
SQL Injection
|
CVE-2008-2688
|
2017-09-29 10:31 |
2008-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256938
|
- |
|
browsercrm
|
browsercrm
|
PHP remote file inclusion vulnerability in pub/clients.php in BrowserCRM 5.002.00 allows remote attackers to execute arbitrary PHP code via a URL in the bcrm_pub_root parameter.
|
CWE-94
Code Injection
|
CVE-2008-2689
|
2017-09-29 10:31 |
2008-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256939
|
- |
|
jiro
|
faq_manager_experience
|
SQL injection vulnerability in read.asp in JiRo's FAQ Manager eXperience 1.0 allows remote attackers to execute arbitrary SQL commands via the fID parameter.
|
CWE-89
SQL Injection
|
CVE-2008-2691
|
2017-09-29 10:31 |
2008-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256940
|
- |
|
joomla
|
com_yvcomment
|
SQL injection vulnerability in the yvComment (com_yvcomment) component 1.16.0 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the ArticleID parameter in a commen…
|
CWE-89
SQL Injection
|
CVE-2008-2692
|
2017-09-29 10:31 |
2008-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|