257941
|
- |
|
miniweb_http_server
|
miniweb_http_server
|
Heap-based buffer overflow in the _mwProcessReadSocket function in http.c in MiniWeb HTTP Server 0.8.19 allows remote attackers to execute arbitrary code via a long URI.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2008-0337
|
2017-09-29 10:30 |
2008-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257942
|
- |
|
miniweb_http_server
|
miniweb_http_server
|
Directory traversal vulnerability in the mwGetLocalFileName function in http.c in MiniWeb HTTP Server 0.8.19 allows remote attackers to read arbitrary files and list arbitrary directories via a (1) .…
|
CWE-22
Path Traversal
|
CVE-2008-0338
|
2017-09-29 10:30 |
2008-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257943
|
- |
|
evilsentinel
|
evilsentinel
|
admin/index.php in Evilsentinel 1.0.9 and earlier sends a redirect to the web browser but does not exit, which allows remote attackers to gain administrative privileges and make arbitrary configurati…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-0350
|
2017-09-29 10:30 |
2008-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257944
|
- |
|
evilsentinel
|
evilsentinel
|
admin/config.php in Evilsentinel 1.0.9 and earlier allows remote attackers to bypass the CAPTCHA test by omitting the es_security_captcha parameter and not invoking captcha.php.
|
CWE-287
Improper Authentication
|
CVE-2008-0351
|
2017-09-29 10:30 |
2008-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257945
|
- |
|
linux
|
linux_kernel
|
The Linux kernel 2.6.20 through 2.6.21.1 allows remote attackers to cause a denial of service (panic) via a certain IPv6 packet, possibly involving the Jumbo Payload hop-by-hop option (jumbogram).
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2008-0352
|
2017-09-29 10:30 |
2008-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257946
|
- |
|
php-residence
|
php-residence
|
SQL injection vulnerability in visualizza_tabelle.php in php-residence 0.7.2 and 1.0 allows remote attackers to execute arbitrary SQL commands via the cognome_cerca parameter. NOTE: some of these de…
|
CWE-89
SQL Injection
|
CVE-2008-0353
|
2017-09-29 10:30 |
2008-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257947
|
- |
|
phpecho_cms
|
phpecho_cms
|
SQL injection vulnerability in index.php in the forum module in PHPEcho CMS, probably 2.0-rc3 and earlier, allows remote attackers to execute arbitrary SQL commands via the id parameter in a section …
|
CWE-89
SQL Injection
|
CVE-2008-0355
|
2017-09-29 10:30 |
2008-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257948
|
- |
|
galaxyscripts
|
mini_file_host
|
Directory traversal vulnerability in pages/upload.php in Galaxyscripts Mini File Host 1.2.1 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal se…
|
CWE-22
Path Traversal
|
CVE-2008-0357
|
2017-09-29 10:30 |
2008-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257949
|
- |
|
pixelpost
|
pixelpost
|
SQL injection vulnerability in index.php in Pixelpost 1.7 allows remote attackers to execute arbitrary SQL commands via the parent_id parameter.
|
CWE-89
SQL Injection
|
CVE-2008-0358
|
2017-09-29 10:30 |
2008-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257950
|
- |
|
alilg
|
alitalk
|
Multiple SQL injection vulnerabilities in aliTalk 1.9.1.1, when magic_quotes_gpc is disabled, allow remote authenticated users to execute arbitrary SQL commands via (1) the mohit parameter to (a) inc…
|
CWE-89
SQL Injection
|
CVE-2008-0371
|
2017-09-29 10:30 |
2008-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|