256461
|
- |
|
availscript
|
availscript_article_script
|
Unrestricted file upload vulnerability in "Add Pen/Author Name" feature in addpen.php in AvailScript Article Script allows remote authenticated users to execute arbitrary code by uploading a file wit…
|
CWE-94
Code Injection
|
CVE-2008-6900
|
2017-09-29 10:33 |
2009-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256462
|
- |
|
2532gigs
|
2532gigs
|
Multiple directory traversal vulnerabilities in 2532designs 2532|Gigs 1.2.2 Stable, when register_globals is enabled and magic_quotes_gpc is disabled, allow remote attackers to include and execute ar…
|
CWE-22
Path Traversal
|
CVE-2008-6901
|
2017-09-29 10:33 |
2009-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256463
|
- |
|
2532gigs
|
2532gigs
|
Unrestricted file upload vulnerability in upload_flyer.php in 2532designs 2532|Gigs 1.2.2 Stable allows remote attackers to execute arbitrary code by uploading a file with an executable extension, th…
|
CWE-94
Code Injection
|
CVE-2008-6902
|
2017-09-29 10:33 |
2009-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256464
|
- |
|
babbleboard
|
babbleboard
|
Cross-site request forgery (CSRF) vulnerability in index.php in BabbleBoard 1.1.6 allows remote authenticated users to hijack the authentication of administrators for requests that delete (1) categor…
|
CWE-352
Origin Validation Error
|
CVE-2008-6905
|
2017-09-29 10:33 |
2009-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256465
|
- |
|
babbleboard
|
babbleboard
|
Cross-site scripting (XSS) vulnerability in index.php in BabbleBoard 1.1.6 allows remote attackers to inject arbitrary web script or HTML via the username.
|
CWE-79
Cross-site Scripting
|
CVE-2008-6906
|
2017-09-29 10:33 |
2009-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256466
|
- |
|
2532gigs
|
2532gigs
|
Multiple SQL injection vulnerabilities in checkuser.php in 2532designs 2532|Gigs 1.2.2 Stable, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) …
|
CWE-89
SQL Injection
|
CVE-2008-6907
|
2017-09-29 10:33 |
2009-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256467
|
- |
|
brewblogger
|
brewblogger
|
SQL injection vulnerability in the authenticateUser function in includes/authentication.inc.php in BrewBlogger (BB) 2.1.0.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbi…
|
CWE-89
SQL Injection
|
CVE-2008-6911
|
2017-09-29 10:33 |
2009-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256468
|
- |
|
zeeways
|
shaadiclone
|
Zeeways SHAADICLONE 2.0 allows remote attackers to bypass authentication and gain administrative privileges via a direct request to admin/home.php.
|
CWE-287
Improper Authentication
|
CVE-2008-6912
|
2017-09-29 10:33 |
2009-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256469
|
- |
|
zeeways
|
zeejobsite
|
Unrestricted file upload vulnerability in editresume_next.php in Zeeways ZEEJOBSITE 2.0 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as…
|
CWE-20
Improper Input Validation
|
CVE-2008-6913
|
2017-09-29 10:33 |
2009-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256470
|
- |
|
zeeways
|
zeeproperty
|
Unrestricted file upload vulnerability in viewprofile.php in Zeeways ZEEPROPERTY 1.0 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-6914
|
2017-09-29 10:33 |
2009-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|