257721
|
- |
|
preprojects
|
pre_ads_portal
|
homeadmin/adminhome.php in Pre ADS Portal 2.0 and earlier does not require administrative authentication, which allows remote attackers to have an unspecified impact via a direct request.
|
CWE-287
Improper Authentication
|
CVE-2008-6716
|
2017-09-29 10:33 |
2009-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257722
|
- |
|
uochm
|
signup
|
U&M Software Signup 1.0 and 1.1 does not require administrative authentication for all scripts in the admin/ directory, which allows remote attackers to have an unspecified impact via a direct reques…
|
CWE-287
Improper Authentication
|
CVE-2008-6717
|
2017-09-29 10:33 |
2009-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257723
|
- |
|
uochm
|
justbookit
|
U&M Software JustBookIt 1.0 does not require administrative authentication for all scripts in the admin/ directory, which allows remote attackers to have an unspecified impact via a direct request to…
|
CWE-287
Improper Authentication
|
CVE-2008-6718
|
2017-09-29 10:33 |
2009-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257724
|
- |
|
uochm
|
justlistit
|
U&M Software Event Lister (aka JustListIt) 1.0 does not require administrative authentication for all scripts in the admin/ directory, which allows remote attackers to have an unspecified impact via …
|
CWE-287
Improper Authentication
|
CVE-2008-6719
|
2017-09-29 10:33 |
2009-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257725
|
- |
|
deltascripts
|
php_links
|
SQL injection vulnerability in admin/adm_login.php in DeltaScripts PHP Links 1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the admin_username parameter (aka the admin …
|
CWE-89
SQL Injection
|
CVE-2008-6720
|
2017-09-29 10:33 |
2009-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257726
|
- |
|
ajsquare
|
aj_article
|
SQL injection vulnerability in index.php in AJ Square AJ Article allows remote attackers to execute arbitrary SQL commands via the txtName parameter (aka the username field).
|
CWE-89
SQL Injection
|
CVE-2008-6721
|
2017-09-29 10:33 |
2009-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257727
|
- |
|
turnkeyforms
|
entertainment_portal
|
TurnkeyForms Entertainment Portal 2.0 allows remote attackers to bypass authentication and gain administrative access by setting the adminLogged cookie to Administrator.
|
CWE-287
Improper Authentication
|
CVE-2008-6723
|
2017-09-29 10:33 |
2009-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257728
|
- |
|
cmscout
|
cmscout
|
Multiple SQL injection vulnerabilities in CMScout 2.06 allow remote authenticated users to execute arbitrary SQL commands via the id parameter to (1) index.php in a mythings page (mythings.php) and (…
|
CWE-89
SQL Injection
|
CVE-2008-6725
|
2017-09-29 10:33 |
2009-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257729
|
- |
|
cmscout
|
cmscout
|
Multiple directory traversal vulnerabilities in CMScout 2.06, when register_globals is enabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the bit param…
|
CWE-22
Path Traversal
|
CVE-2008-6726
|
2017-09-29 10:33 |
2009-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257730
|
- |
|
myupb
|
upb
|
Cross-site scripting (XSS) vulnerability in Ultimate PHP Board (UPB) 2.2.2, 2.2.1, and earlier 2.x versions allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP head…
|
CWE-79
Cross-site Scripting
|
CVE-2008-6727
|
2017-09-29 10:33 |
2009-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|