257611
|
- |
|
brian_wilson
|
ol\'bookmarks
|
Directory traversal vulnerability in show.php in ol'bookmarks manager 0.7.5 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the show parameter.
|
CWE-22
Path Traversal
|
CVE-2008-6410
|
2017-09-29 10:33 |
2009-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257612
|
- |
|
explay
|
explay_cms
|
Explay CMS 2.1 and earlier allows remote attackers to bypass authentication and gain administrative access by setting the login cookie to 1.
|
CWE-287
Improper Authentication
|
CVE-2008-6411
|
2017-09-29 10:33 |
2009-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257613
|
- |
|
aj_square
|
aj_auction
|
SQL injection vulnerability in detail.php in AJ Auction Pro Platinum Skin 2 allows remote attackers to execute arbitrary SQL commands via the item_id parameter.
|
CWE-89
SQL Injection
|
CVE-2008-6414
|
2017-09-29 10:33 |
2009-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257614
|
- |
|
socialsitegenerator
|
social_site_generator
|
Multiple SQL injection vulnerabilities in Social Site Generator (SSG) 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) sgc_id parameter to display_blog.php, (2) scm_mem_id par…
|
CWE-89
SQL Injection
|
CVE-2008-6419
|
2017-09-29 10:33 |
2009-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257615
|
- |
|
socialsitegenerator
|
social_site_generator
|
Social Site Generator (SSG) 2.0 allows remote attackers to read arbitrary files via the file parameter to (1) filedload.php, (2) webadmin/download.php, and (3) webadmin/download_file.php.
|
CWE-200
Information Exposure
|
CVE-2008-6420
|
2017-09-29 10:33 |
2009-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257616
|
- |
|
socialsitegenerator
|
social_site_generator
|
PHP remote file inclusion vulnerability in social_game_play.php in Social Site Generator (SSG) 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the path parameter.
|
CWE-94
Code Injection
|
CVE-2008-6421
|
2017-09-29 10:33 |
2009-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257617
|
- |
|
psychostats
|
psychostats
|
Multiple SQL injection vulnerabilities in PsychoStats 2.3, 2.3.1, and 2.3.3 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) weapon.php and (2) map.php.
|
CWE-89
SQL Injection
|
CVE-2008-6422
|
2017-09-29 10:33 |
2009-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257618
|
- |
|
i-apps
|
passwiki
|
Directory traversal vulnerability in passwiki.php in PassWiki 0.9.16 RC3 and earlier allows remote attackers to read arbitrary local files via a .. (dot dot) in the site_id parameter.
|
CWE-22
Path Traversal
|
CVE-2008-6423
|
2017-09-29 10:33 |
2009-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257619
|
- |
|
comicshout
|
comicshout
|
SQL injection vulnerability in news.php in ComicShout 2.8 allows remote attackers to execute arbitrary SQL commands via the news_id parameter, a different vector than CVE-2008-2456.
|
CWE-89
SQL Injection
|
CVE-2008-6425
|
2017-09-29 10:33 |
2009-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257620
|
- |
|
mike_leeper
|
com_prayercenter
|
SQL injection vulnerability in the PrayerCenter (com_prayercenter) component 1.4.9 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a view_req…
|
CWE-89
SQL Injection
|
CVE-2008-6429
|
2017-09-29 10:33 |
2009-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|