257471
|
- |
|
raidenftpd
|
raidenftpd
|
Stack-based buffer overflow in RaidenFTPD 2.4 build 3620 allows remote authenticated users to cause a denial of service (crash) or execute arbitrary code via long (1) CWD and (2) MLST commands.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2008-6186
|
2017-09-29 10:33 |
2009-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257472
|
- |
|
myblog
|
myblog
|
Sam Crew MyBlog stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain sensitive information.
|
CWE-310
Cryptographic Issues
|
CVE-2008-6193
|
2017-09-29 10:33 |
2009-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257473
|
- |
|
kwsphp
|
galerie_module
|
SQL injection vulnerability in index.php in the galerie module for KwsPHP 1.3.456 allows remote attackers to execute arbitrary SQL commands via the id_gal parameter in a gal action.
|
CWE-89
SQL Injection
|
CVE-2008-6197
|
2017-09-29 10:33 |
2009-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257474
|
- |
|
mybboard
|
custom_pages_plugin
|
SQL injection vulnerability in pages.php in Custom Pages 1.0 plugin for MyBulletinBoard (MyBB) allows remote attackers to execute arbitrary SQL commands via the page parameter.
|
CWE-89
SQL Injection
|
CVE-2008-6198
|
2017-09-29 10:33 |
2009-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257475
|
- |
|
2532gigs
|
2532gigs
|
2532designs 2532|Gigs 1.2.2 and earlier allows remote attackers to trigger a backup and obtain sensitive information via a direct request to backup.php, which creates backup.sql under the web root wi…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-6199
|
2017-09-29 10:33 |
2009-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257476
|
- |
|
2532gigs
|
2532gigs
|
Reference links indicate attacker must be authenticated for attack to be successful.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-6199
|
2017-09-29 10:33 |
2009-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257477
|
- |
|
jakob-persson
|
cobalt
|
SQL injection vulnerability in CoBaLT 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter to (1) urun.asp, (2) admin/bayi_listele.asp, (3) admin/urun_grup_listele.asp, …
|
CWE-89
SQL Injection
|
CVE-2008-6202
|
2017-09-29 10:33 |
2009-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257478
|
- |
|
supernet
|
supernet_shop
|
Multiple SQL injection vulnerabilities in SuperNET Shop 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to secure/admin/guncelle.asp, (2) kulad and s…
|
CWE-89
SQL Injection
|
CVE-2008-6204
|
2017-09-29 10:33 |
2009-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257479
|
- |
|
vastal
|
software_zone
|
SQL injection vulnerability in view_product.php in Vastal I-Tech Software Zone allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.
|
CWE-89
SQL Injection
|
CVE-2008-6209
|
2017-09-29 10:33 |
2009-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257480
|
- |
|
dream4
|
koobi
|
SQL injection vulnerability in index.php in dream4 Koobi 4.4 and 5.4 allows remote attackers to execute arbitrary SQL commands via the img_id parameter in the gallerypic page.
|
CWE-89
SQL Injection
|
CVE-2008-6210
|
2017-09-29 10:33 |
2009-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|