259361
|
- |
|
pd9_software
|
megabbs
|
Mulatiple cross-site scripting (XSS) vulnerabilities in PD9 Software MegaBBS 2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) toid parameter to send-private-message.asp a…
|
CWE-79
Cross-site Scripting
|
CVE-2008-2022
|
2017-09-29 10:30 |
2008-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259362
|
- |
|
pd9_software
|
megabbs
|
Multiple SQL injection vulnerabilities in PD9 Software MegaBBS 2.2 allow remote attackers to execute arbitrary SQL commands via the (1) invisible and (2) timeoffset parameters to profile/controlpanel…
|
CWE-89
SQL Injection
|
CVE-2008-2023
|
2017-09-29 10:30 |
2008-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259363
|
- |
|
minibb
|
minibb
|
Cross-site scripting (XSS) vulnerability in index.php in miniBB 2.2, and possibly earlier, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the gla…
|
CWE-79
Cross-site Scripting
|
CVE-2008-2024
|
2017-09-29 10:30 |
2008-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259364
|
- |
|
minibb
|
minibb
|
miniBB 2.2, and possibly earlier, when register_globals is enabled, allows remote attackers to obtain the full path via a direct request to the glang parameter in a registernew action to index.php, w…
|
CWE-200
Information Exposure
|
CVE-2008-2028
|
2017-09-29 10:30 |
2008-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259365
|
- |
|
minibb
|
minibb
|
Multiple SQL injection vulnerabilities in (1) setup_mysql.php and (2) setup_options.php in miniBB 2.2 and possibly earlier, when register_globals is enabled, allow remote attackers to execute arbitra…
|
CWE-89
SQL Injection
|
CVE-2008-2029
|
2017-09-29 10:30 |
2008-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259366
|
- |
|
aspindir
|
angelo-emlak
|
Multiple SQL injection vulnerabilities in Angelo-Emlak 1.0 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) hpz/profil.asp and (2) hpz/prodetail.asp.
|
CWE-89
SQL Injection
|
CVE-2008-2047
|
2017-09-29 10:30 |
2008-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259367
|
- |
|
aspindir
|
angelo-emlak
|
Cross-site scripting (XSS) vulnerability in hpz/admin/Default.asp in Angelo-Emlak 1.0 allows remote attackers to inject arbitrary web script or HTML via the sayfa parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2008-2048
|
2017-09-29 10:30 |
2008-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259368
|
- |
|
joovili
|
joovili
|
SQL injection vulnerability in browse.videos.php in Joovili 3.1 allows remote attackers to execute arbitrary SQL commands via the category parameter.
|
CWE-89
SQL Injection
|
CVE-2008-2063
|
2017-09-29 10:30 |
2008-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259369
|
- |
|
yourfreeworld
|
jokes_site_script
|
SQL injection vulnerability in jokes.php in YourFreeWorld Jokes Site Script allows remote attackers to execute arbitrary SQL commands via the catagorie parameter.
|
CWE-89
SQL Injection
|
CVE-2008-2065
|
2017-09-29 10:30 |
2008-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259370
|
- |
|
xzero_scripts
|
xzero_community_classifieds
|
PHP remote file inclusion vulnerability in config.inc.php in XZero Community Classifieds 4.95.11 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path_escape paramet…
|
CWE-94
Code Injection
|
CVE-2007-6568
|
2017-09-29 10:30 |
2007-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|