256791
|
- |
|
vbulletin
|
vbgooglemap
|
SQL injection vulnerability in VBGooglemap Hotspot Edition 1.0.3, a vBulletin module, allows remote attackers to execute arbitrary SQL commands via the mapid parameter in a showdetails action to (1) …
|
CWE-89
SQL Injection
|
CVE-2008-4706
|
2017-09-29 10:32 |
2008-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256792
|
- |
|
sylvain_pasquet
|
bbzl_php
|
Directory traversal vulnerability in index.php in BbZL.PhP 0.92 allows remote attackers to access unauthorized directories via a .. (dot dot) in the lien_2 parameter.
|
CWE-22
Path Traversal
|
CVE-2008-4707
|
2017-09-29 10:32 |
2008-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256793
|
- |
|
sylvain_pasquet
|
bbzl.php
|
BbZL.PhP 0.92 allows remote attackers to bypass authentication and gain administrative access by setting the phorum_admin_session cookie to 1.
|
CWE-287
Improper Authentication
|
CVE-2008-4708
|
2017-09-29 10:32 |
2008-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256794
|
- |
|
pilot_group
|
etraining
|
SQL injection vulnerability in news_read.php in Pilot Group (PG) eTraining allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2008-4709
|
2017-09-29 10:32 |
2008-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256795
|
- |
|
joovili
|
joovili
|
SQL injection vulnerability in Joovili 3.0 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter to (1) view.blog.php, (2) vie…
|
CWE-89
SQL Injection
|
CVE-2008-4711
|
2017-09-29 10:32 |
2008-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256796
|
- |
|
lnblog
|
lnblog
|
Directory traversal vulnerability in pages/showblog.php in LnBlog 0.9.0 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (…
|
CWE-22
Path Traversal
|
CVE-2008-4712
|
2017-09-29 10:32 |
2008-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256797
|
- |
|
212cafe
|
212cafeboard
|
SQL injection vulnerability in view.php in 212cafe Board 0.07 allows remote attackers to execute arbitrary SQL commands via the qID parameter.
|
CWE-89
SQL Injection
|
CVE-2008-4713
|
2017-09-29 10:32 |
2008-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256798
|
- |
|
atomic_photo_album
|
atomic_photo_album
|
Atomic Photo Album 1.1.0 pre4 does not properly handle the apa_cookie_login and apa_cookie_password cookies, which probably allows remote attackers to bypass authentication and gain administrative ac…
|
CWE-287
Improper Authentication
|
CVE-2008-4714
|
2017-09-29 10:32 |
2008-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256799
|
- |
|
scriptdemo
|
php-lance
|
SQL injection vulnerability in show.php in BitmixSoft PHP-Lance 1.52 allows remote attackers to execute arbitrary SQL commands via the catid parameter.
|
CWE-89
SQL Injection
|
CVE-2008-4716
|
2017-09-29 10:32 |
2008-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256800
|
- |
|
zeeways
|
zeelyrics
|
SQL injection vulnerability in bannerclick.php in ZEELYRICS 2.0 allows remote attackers to execute arbitrary SQL commands via the adid parameter.
|
CWE-89
SQL Injection
|
CVE-2008-4717
|
2017-09-29 10:32 |
2008-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|