263661
|
- |
|
youtube_blog
|
youtube_blog
|
SQL injection vulnerability in info.php in C. Desseno YouTube Blog (ytb) 0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2008-3307. NO…
|
CWE-89
SQL Injection
|
CVE-2008-3306
|
2017-08-8 10:31 |
2008-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
263662
|
- |
|
lemoncms
|
lemon_cms
|
Directory traversal vulnerability in lemon_includes/FCKeditor/editor/filemanager/browser/browser.php in Lemon CMS 1.10 allows remote attackers to include and execute arbitrary local files via a .. (d…
|
CWE-22
Path Traversal
|
CVE-2008-3312
|
2017-08-8 10:31 |
2008-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
263663
|
- |
|
creacms
|
creacms
|
Multiple PHP remote file inclusion vulnerabilities in CreaCMS 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the (1) cfg[document_uri] parameter to _administration/edition_arti…
|
CWE-94
Code Injection
|
CVE-2008-3313
|
2017-08-8 10:31 |
2008-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
263664
|
- |
|
portalparts
|
forum_plugin
|
Cross-site scripting (XSS) vulnerability in the search feature in the Forum plugin before 2.7.1 for Geeklog allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, pro…
|
CWE-79
Cross-site Scripting
|
CVE-2008-3316
|
2017-08-8 10:31 |
2008-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
263665
|
- |
|
edgewall_software
|
trac
|
Cross-site scripting (XSS) vulnerability in the wiki engine in Trac before 0.10.5 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2008-3328
|
2017-08-8 10:31 |
2008-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
263666
|
- |
|
twibright
|
links
|
Unspecified vulnerability in Links before 2.1, when "only proxies" is enabled, has unknown impact and attack vectors related to providing "URLs to external programs."
|
CWE-59 NVD-CWE-noinfo
Link Following
|
CVE-2008-3329
|
2017-08-8 10:31 |
2008-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
263667
|
- |
|
debian
|
horde turba
|
Cross-site scripting (XSS) vulnerability in services/obrowser/index.php in Horde 3.2 and Turba 2.2 allows remote attackers to inject arbitrary web script or HTML via the contact name.
|
CWE-79
Cross-site Scripting
|
CVE-2008-3330
|
2017-08-8 10:31 |
2008-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
263668
|
- |
|
mantis
|
mantis
|
Directory traversal vulnerability in core/lang_api.php in Mantis before 1.1.2 allows remote attackers to include and execute arbitrary files via the language parameter to the user preferences page (a…
|
CWE-22
Path Traversal
|
CVE-2008-3333
|
2017-08-8 10:31 |
2008-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
263669
|
- |
|
mybb
|
mybb
|
Cross-site scripting (XSS) vulnerability in MyBB 1.2.x before 1.2.14 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly involving search.php.
|
CWE-79
Cross-site Scripting
|
CVE-2008-3334
|
2017-08-8 10:31 |
2008-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
263670
|
- |
|
punbb
|
punbb
|
Unspecified vulnerability in PunBB before 1.2.19 allows remote attackers to inject arbitrary SMTP commands via unknown vectors.
|
NVD-CWE-noinfo CWE-94
Code Injection
|
CVE-2008-3335
|
2017-08-8 10:31 |
2008-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|