257171
|
- |
|
phpauctions
|
phpauctions
|
SQL injection vulnerability in profile.php in PHPAuctions.info PHPAuctions (aka PHPAuctionSystem) allows remote attackers to execute arbitrary SQL commands via the auction_id parameter, a different v…
|
CWE-89
SQL Injection
|
CVE-2008-6663
|
2017-09-29 10:33 |
2009-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257172
|
- |
|
anantasoft
|
ananta_cms
|
change.php in Ananta CMS 1.0b5, with magic_quotes_gpc disabled, allows remote attackers to gain administrator privileges via a crafted email parameter, possibly related to code injection.
|
CWE-94
Code Injection
|
CVE-2008-6665
|
2017-09-29 10:33 |
2009-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257173
|
- |
|
marc_melvin
|
a\+_php_scripts_news_management_system
|
A+ PHP Scripts News Management System (NMS) allows remote attackers to bypass authentication and gain administrator privileges by setting the mobsuser and mobspass cookies to 1.
|
CWE-287
Improper Authentication
|
CVE-2008-6667
|
2017-09-29 10:33 |
2009-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257174
|
- |
|
dirk_bartley
|
nweb2fax
|
Multiple directory traversal vulnerabilities in nweb2fax 0.2.7 and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) id parameter to comm.php and (2) var_filename p…
|
CWE-22
Path Traversal
|
CVE-2008-6668
|
2017-09-29 10:33 |
2009-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257175
|
- |
|
dirk_bartley
|
nweb2fax
|
viewrq.php in nweb2fax 0.2.7 and earlier allows remote attackers to execute arbitrary code via shell metacharacters in the var_filename parameter in a (1) tif or (2) pdf format action.
|
CWE-78
OS Command
|
CVE-2008-6669
|
2017-09-29 10:33 |
2009-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257176
|
- |
|
yourfreeworld
|
apartment_search_script
|
Cross-site scripting (XSS) vulnerability in listtest.php in Apartment Search Script allows remote attackers to inject arbitrary web script or HTML via the r parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2008-6683
|
2017-09-29 10:33 |
2009-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257177
|
- |
|
yourfreeworld
|
apartment_search_script
|
Unrestricted file upload vulnerability in editimage.php in Apartment Search Script allows remote attackers to execute arbitrary code by uploading a file with an executable extension and a GIF header,…
|
CWE-20
Improper Input Validation
|
CVE-2008-6684
|
2017-09-29 10:33 |
2009-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257178
|
- |
|
butterflymedia
|
butterfly_organizer
|
Multiple cross-site scripting (XSS) vulnerabilities in Butterfly Organizer 2.0.0 allow remote attackers to inject arbitrary web script or HTML via the (1) mytable parameter to view.php, (2) mytable p…
|
CWE-79
Cross-site Scripting
|
CVE-2008-6700
|
2017-09-29 10:33 |
2009-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257179
|
- |
|
preprojects
|
pre_ads_portal
|
Multiple cross-site scripting (XSS) vulnerabilities in Pre ADS Portal 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the msg parameter to (1) homeadmin/adminhome.ph…
|
CWE-79
Cross-site Scripting
|
CVE-2008-6715
|
2017-09-29 10:33 |
2009-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257180
|
- |
|
preprojects
|
pre_ads_portal
|
homeadmin/adminhome.php in Pre ADS Portal 2.0 and earlier does not require administrative authentication, which allows remote attackers to have an unspecified impact via a direct request.
|
CWE-287
Improper Authentication
|
CVE-2008-6716
|
2017-09-29 10:33 |
2009-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|