257131
|
- |
|
sco
|
reliantha unixware
|
Merge mcd in ReliantHA 1.1.4 in SCO UnixWare 7.1.4 allows local users to gain root privileges via a crafted -d argument that contains .. (dot dot) sequences that point to a directory containing a fil…
|
CWE-20
Improper Input Validation
|
CVE-2008-6559
|
2017-09-29 10:33 |
2009-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257132
|
- |
|
funscripts
|
red_reservations
|
The Red_Reservations script for ColdFusion stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database via a direct reques…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-6580
|
2017-09-29 10:33 |
2009-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257133
|
- |
|
phpaddedit
|
phpaddedit
|
login.php in PhpAddEdit 1.3 allows remote attackers to bypass authentication and gain administrative access by setting the addedit cookie parameter.
|
CWE-287
Improper Authentication
|
CVE-2008-6581
|
2017-09-29 10:33 |
2009-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257134
|
- |
|
miniweb2
|
miniweb
|
SQL injection vulnerability in index.php in Miniweb 2.0 allows remote attackers to execute arbitrary SQL commands via the username parameter in a login action.
|
CWE-89
SQL Injection
|
CVE-2008-6582
|
2017-09-29 10:33 |
2009-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257135
|
- |
|
bsplayer
|
bs.player
|
Buffer overflow in BS.player 2.27 build 959 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in a .SRT file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2008-6583
|
2017-09-29 10:33 |
2009-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257136
|
- |
|
picoflat
|
picoflat_cms
|
Directory traversal vulnerability in index.php in PicoFlat CMS 0.5.9 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the pagina parameter, a different vulne…
|
CWE-22
Path Traversal
|
CVE-2008-6604
|
2017-09-29 10:33 |
2009-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257137
|
- |
|
2wire
|
1701hg 1800hw 2071hg 2700hg
|
Cross-site request forgery (CSRF) vulnerability in the xslt script in the web-based management interface on the 2wire 1701HG, 1800HW, 2071HG, and 2700HG with firmware 3.17.5, 3.7.1, 4.25.19, or 5.29.…
|
CWE-352
Origin Validation Error
|
CVE-2008-6605
|
2017-09-29 10:33 |
2009-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257138
|
- |
|
matpo
|
matpo_link
|
SQL injection vulnerability in view.php in MatPo Link 1.2 Beta allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2008-6606
|
2017-09-29 10:33 |
2009-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257139
|
- |
|
matpo
|
matpo_link
|
Cross-site scripting (XSS) vulnerability in view.php in MatPo Link 1.2 Beta allows remote attackers to inject arbitrary web script or HTML via the thema parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2008-6607
|
2017-09-29 10:33 |
2009-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257140
|
- |
|
developiteasy
|
events_calendar
|
Multiple SQL injection vulnerabilities in DevelopItEasy Events Calendar 1.2 allow remote attackers to execute arbitrary SQL commands via (1) the user_name parameter (aka user field) to admin/index.ph…
|
CWE-89
SQL Injection
|
CVE-2008-6608
|
2017-09-29 10:33 |
2009-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|