257831
|
- |
|
ftrsoft
|
fast_click_sql_lite
|
PHP remote file inclusion vulnerability in init.php in Fast Click SQL Lite 1.1.7, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the CFG[CDIR] pa…
|
CWE-94
Code Injection
|
CVE-2008-4624
|
2017-09-29 10:32 |
2008-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257832
|
- |
|
shiftthis
|
shifthis_newsletter
|
SQL injection vulnerability in stnl_iframe.php in the ShiftThis Newsletter (st_newsletter) plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the newsletter parameter,…
|
CWE-89
SQL Injection
|
CVE-2008-4625
|
2017-09-29 10:32 |
2008-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257833
|
- |
|
zirkon_box
|
yappa-ng
|
Directory traversal vulnerability in index.php in Fritz Berger yet another php photo album - next generation (yappa-ng) 2.3.2 and possibly other versions through 2.3.3-beta0, when magic_quotes_gpc is…
|
CWE-22
Path Traversal
|
CVE-2008-4626
|
2017-09-29 10:32 |
2008-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257834
|
- |
|
rgallery
|
rgallery_plugin
|
SQL injection vulnerability in the rGallery plugin 1.09 for WoltLab Burning Board (WBB) allows remote attackers to execute arbitrary SQL commands via the itemID parameter in the RGalleryImageWrapper …
|
CWE-89
SQL Injection
|
CVE-2008-4627
|
2017-09-29 10:32 |
2008-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257835
|
- |
|
mywebland
|
minibloggie
|
SQL injection vulnerability in del.php in myWebland miniBloggie 1.0 allows remote attackers to execute arbitrary SQL commands via the post_id parameter.
|
CWE-89
SQL Injection
|
CVE-2008-4628
|
2017-09-29 10:32 |
2008-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257836
|
- |
|
kure
|
kure
|
Multiple directory traversal vulnerabilities in index.php in Kure 0.6.3, when magic_quotes_gpc is disabled, allow remote attackers to read and possibly execute arbitrary local files via a .. (dot dot…
|
CWE-22
Path Traversal
|
CVE-2008-4632
|
2017-09-29 10:32 |
2008-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257837
|
- |
|
astrospaces
|
astrospaces
|
SQL injection vulnerability in profile.php in AstroSPACES 1.1.1 allows remote attackers to execute arbitrary SQL commands via the id parameter in a view action.
|
CWE-89
SQL Injection
|
CVE-2008-4642
|
2017-09-29 10:32 |
2008-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257838
|
- |
|
mywebland
|
mystats
|
SQL injection vulnerability in hits.php in myWebland myStats allows remote attackers to execute arbitrary SQL commands via the sortby parameter.
|
CWE-89
SQL Injection
|
CVE-2008-4643
|
2017-09-29 10:32 |
2008-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257839
|
- |
|
mywebland
|
mystats
|
hits.php in myWebland myStats allows remote attackers to bypass IP address restrictions via a modified X-Forwarded-For HTTP header.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-4644
|
2017-09-29 10:32 |
2008-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257840
|
- |
|
phpwebgallery
|
phpwebgallery
|
plugins/event_tracer/event_list.php in PhpWebGallery 1.7.2 and earlier allows remote authenticated administrators to execute arbitrary PHP code via PHP sequences in the sort parameter, which is proce…
|
CWE-94
Code Injection
|
CVE-2008-4645
|
2017-09-29 10:32 |
2008-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|