256931
|
- |
|
clanlite
|
clanlite
|
Cross-site scripting (XSS) vulnerability in service/calendrier.php in ClanLite 2.2006.05.20 allows remote attackers to inject arbitrary web script or HTML via the annee parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2008-5214
|
2017-09-29 10:32 |
2008-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256932
|
- |
|
clanlite
|
clanlite
|
SQL injection vulnerability in service/profil.php in ClanLite 2.2006.05.20 allows remote attackers to execute arbitrary SQL commands via the link parameter.
|
CWE-89
SQL Injection
|
CVE-2008-5215
|
2017-09-29 10:32 |
2008-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256933
|
- |
|
aj_square
|
zeuscart
|
SQL injection vulnerability in category_list.php in AJ Square ZeusCart 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter.
|
CWE-89
SQL Injection
|
CVE-2008-5216
|
2017-09-29 10:32 |
2008-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256934
|
- |
|
phpc0d3r
|
txtcms
|
Directory traversal vulnerability in index.php in txtCMS 0.3, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files v…
|
CWE-22
Path Traversal
|
CVE-2008-5217
|
2017-09-29 10:32 |
2008-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256935
|
- |
|
scriptsez
|
freeze_greetings
|
ScriptsEz FREEze Greetings 1.0 stores pwd.txt under the web root with insufficient access control, which allows remote attackers to obtain cleartext passwords.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-5218
|
2017-09-29 10:32 |
2008-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256936
|
- |
|
videoscript
|
videoscript
|
The password change feature (admin/cp.php) in VideoScript 4.0.1.50 and earlier does not check for administrative authentication and does not require knowledge of the original password, which allows r…
|
CWE-287
Improper Authentication
|
CVE-2008-5219
|
2017-09-29 10:32 |
2008-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256937
|
- |
|
wportfolio
|
wportfolio
|
Unrestricted file upload vulnerability in admin/upload_form.php in wPortfolio 0.3 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then …
|
CWE-20
Improper Input Validation
|
CVE-2008-5220
|
2017-09-29 10:32 |
2008-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256938
|
- |
|
wportfolio
|
wportfolio
|
The account_save action in admin/userinfo.php in wPortfolio 0.3 and earlier does not require authentication and does not require knowledge of the original password, which allows remote attackers to c…
|
CWE-287
Improper Authentication
|
CVE-2008-5221
|
2017-09-29 10:32 |
2008-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256939
|
- |
|
airvae
|
commerce
|
SQL injection vulnerability in index.php in Airvae Commerce 3.0 allows remote attackers to execute arbitrary SQL commands via the pid parameter.
|
CWE-89
SQL Injection
|
CVE-2008-5223
|
2017-09-29 10:32 |
2008-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256940
|
- |
|
mambads mambo
|
mambads mambo
|
SQL injection vulnerability in the MambAds (com_mambads) component 1.0 RC1 Beta and 1.0 RC1 for Mambo allows remote attackers to execute arbitrary SQL commands via the ma_cat parameter in a view acti…
|
CWE-89
SQL Injection
|
CVE-2008-5226
|
2017-09-29 10:32 |
2008-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|