257421
|
- |
|
gradman
|
gradman
|
Directory traversal vulnerability in info.php in GradMan 0.1.3 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the tabla parameter, a different …
|
CWE-22
Path Traversal
|
CVE-2008-0393
|
2017-09-29 10:30 |
2008-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257422
|
- |
|
citadel
|
smtp
|
Buffer overflow in Citadel SMTP server 7.10 and earlier allows remote attackers to execute arbitrary code via a long RCPT TO command, which is not properly handled by the makeuserkey function. NOTE:…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2008-0394
|
2017-09-29 10:30 |
2008-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257423
|
- |
|
aflog.org
|
aflog
|
Multiple SQL injection vulnerabilities in aflog 1.01, and possibly earlier versions, allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to comments.php and (2) an unspe…
|
CWE-89
SQL Injection
|
CVE-2008-0397
|
2017-09-29 10:30 |
2008-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257424
|
- |
|
aflog
|
aflog
|
Cross-site scripting (XSS) vulnerability in aflog 1.01, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the comment form.
|
CWE-79
Cross-site Scripting
|
CVE-2008-0398
|
2017-09-29 10:30 |
2008-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257425
|
- |
|
toshiba
|
surveillix
|
Multiple buffer overflows in Toshiba Surveillance (Surveillix) RecordSend ActiveX control (MeIpCamX.DLL 1.0.0.4) allow remote attackers to execute arbitrary code via long arguments to the (1) SetPort…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2008-0399
|
2017-09-29 10:30 |
2008-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257426
|
- |
|
invision_power_services
|
invision_gallery
|
SQL injection vulnerability in Invision Gallery 2.0.7 and earlier allows remote attackers to execute arbitrary SQL commands via the album parameter in a rate command.
|
CWE-89
SQL Injection
|
CVE-2008-0421
|
2017-09-29 10:30 |
2008-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257427
|
- |
|
lama
|
lama_software
|
Multiple PHP remote file inclusion vulnerabilities in Lama Software allow remote attackers to execute arbitrary PHP code via a URL in the MY_CONF[classRoot] parameter to (1) inc.steps.access_error.ph…
|
CWE-94
Code Injection
|
CVE-2008-0423
|
2017-09-29 10:30 |
2008-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257428
|
- |
|
mooseguy_blog_system
|
mgbs
|
SQL injection vulnerability in blog.php in Mooseguy Blog System (MGBS) 1.0 allows remote attackers to execute arbitrary SQL commands via the month parameter.
|
CWE-89
SQL Injection
|
CVE-2008-0424
|
2017-09-29 10:30 |
2008-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257429
|
- |
|
frimousse
|
frimousse
|
Absolute path traversal vulnerability in explorerdir.php in Frimousse 0.0.2 allows remote attackers to read arbitrary files and list arbitrary directories via a full pathname in the name parameter.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-0425
|
2017-09-29 10:30 |
2008-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257430
|
- |
|
alstrasoft
|
forum_pay_per_post_exchange
|
SQL injection vulnerability in index.php in AlstraSoft Forum Pay Per Post Exchange 2.0 allows remote attackers to execute arbitrary SQL commands via the catid parameter in a forum_catview action.
|
CWE-89
SQL Injection
|
CVE-2008-0429
|
2017-09-29 10:30 |
2008-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|