257731
|
- |
|
coppermine-gallery
|
coppermine_photo_gallery
|
themes/sample/theme.php in Coppermine Photo Gallery (CPG) 1.4.18 and earlier allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an er…
|
CWE-94
Code Injection
|
CVE-2008-3481
|
2017-09-29 10:31 |
2008-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257732
|
- |
|
coppermine-gallery
|
coppermine_photo_gallery
|
as per vendor link: http://coppermine-gallery.net/
"The development team is releasing a security update for Coppermine in order to counter a recently discovered injection vulnerability. It is import…
|
CWE-94
Code Injection
|
CVE-2008-3481
|
2017-09-29 10:31 |
2008-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257733
|
- |
|
estoreaff
|
estoreaff
|
SQL injection vulnerability in eStoreAff 0.1 allows remote attackers to execute arbitrary SQL commands via the cid parameter in a showcat action to index.php.
|
CWE-89
SQL Injection
|
CVE-2008-3484
|
2017-09-29 10:31 |
2008-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257734
|
- |
|
coppermine-gallery
|
coppermine_photo_gallery
|
Directory traversal vulnerability in the user_get_profile function in include/functions.inc.php in Coppermine Photo Gallery (CPG) 1.4.18 and earlier, when the charset is utf-8, allows remote attacker…
|
CWE-22
Path Traversal
|
CVE-2008-3486
|
2017-09-29 10:31 |
2008-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257735
|
- |
|
coppermine-gallery
|
coppermine_photo_gallery
|
http://secunia.com/advisories/31295:
"Successful exploitation requires that "Character encoding" is set to "Unicode (recommended) (utf-8)", which is the default value."
|
CWE-22
Path Traversal
|
CVE-2008-3486
|
2017-09-29 10:31 |
2008-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257736
|
- |
|
phpauctions
|
phpauction_gpl_enhanced
|
SQL injection vulnerability in profile.php in PHPAuction GPL Enhanced 2.51 allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2008-3487
|
2017-09-29 10:31 |
2008-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257737
|
- |
|
phpx
|
phpx
|
SQL injection vulnerability in checkCookie function in includes/functions.inc.php in PHPX 3.5.16 allows remote attackers to execute arbitrary SQL commands via a PXL cookie.
|
CWE-89
SQL Injection
|
CVE-2008-3489
|
2017-09-29 10:31 |
2008-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257738
|
- |
|
e-topbiz
|
online_dating
|
SQL injection vulnerability in members/mail.php in E-topbiz Online Dating 3 1.0 allows remote authenticated users to execute arbitrary SQL commands via the mail_id parameter in a veiw action.
|
CWE-89
SQL Injection
|
CVE-2008-3490
|
2017-09-29 10:31 |
2008-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257739
|
- |
|
scripts24
|
ipost itgp
|
SQL injection vulnerability in go.php in Scripts24 iPost 1.0.1 and iTGP 1.0.4 allows remote attackers to execute arbitrary SQL commands via the id parameter in a report action.
|
CWE-89
SQL Injection
|
CVE-2008-3491
|
2017-09-29 10:31 |
2008-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257740
|
- |
|
realvnc
|
realvnc_windows_client
|
vncviewer.exe in RealVNC Windows Client 4.1.2.0 allows remote VNC servers to cause a denial of service (application crash) via a crafted frame buffer update packet.
|
CWE-20
Improper Input Validation
|
CVE-2008-3493
|
2017-09-29 10:31 |
2008-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|