258821
|
- |
|
cmsimple
|
cmsimple
|
Upgrade requires login when downloads link is clicked from X-Force site.
|
CWE-22
Path Traversal
|
CVE-2008-2650
|
2017-09-29 10:31 |
2008-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258822
|
- |
|
joomla
|
com_joobb
|
SQL injection vulnerability in the Joomla! Bulletin Board (aka Joo!BB or com_joobb) component 0.5.9 for Joomla! allows remote attackers to execute arbitrary SQL commands via the forum parameter in a …
|
CWE-89
SQL Injection
|
CVE-2008-2651
|
2017-09-29 10:31 |
2008-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258823
|
- |
|
powie
|
pnews
|
SQL injection vulnerability in index.php in Powie pNews 2.08 and 2.10, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the shownews parameter.
|
CWE-89
SQL Injection
|
CVE-2008-2673
|
2017-09-29 10:31 |
2008-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258824
|
- |
|
joomla
|
com_news_portal joomla
|
SQL injection vulnerability in the iJoomla News Portal (com_news_portal) component 1.0 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter to in…
|
CWE-89
SQL Injection
|
CVE-2008-2676
|
2017-09-29 10:31 |
2008-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258825
|
- |
|
telephone
|
telephone_directory_2008
|
Cross-site scripting (XSS) vulnerability in edit1.php in Telephone Directory 2008 allows remote attackers to inject arbitrary web script or HTML via the action parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2008-2677
|
2017-09-29 10:31 |
2008-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258826
|
- |
|
telephone
|
telephone_directory_2008
|
Multiple SQL injection vulnerabilities in Telephone Directory 2008, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) code parameter in a confirm…
|
CWE-89
SQL Injection
|
CVE-2008-2678
|
2017-09-29 10:31 |
2008-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258827
|
- |
|
realm_project
|
realm_cms
|
SQL injection vulnerability in the KeyWordsList function in _includes/inc_routines.asp in Realm CMS 2.3 and earlier allows remote attackers to execute arbitrary SQL commands via the kwrd parameter in…
|
CWE-89
SQL Injection
|
CVE-2008-2679
|
2017-09-29 10:31 |
2008-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258828
|
- |
|
realm_project
|
realm_cms
|
Multiple cross-site scripting (XSS) vulnerabilities in _db/compact.asp in Realm CMS 2.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) CmpctedDB and (2) Boyut p…
|
CWE-79
Cross-site Scripting
|
CVE-2008-2680
|
2017-09-29 10:31 |
2008-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258829
|
- |
|
realm_project
|
realm_cms
|
Realm CMS 2.3 and earlier allows remote attackers to obtain sensitive information via a direct request to _db/compact.asp, which reveals the database path in an error message.
|
CWE-200
Information Exposure
|
CVE-2008-2681
|
2017-09-29 10:31 |
2008-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258830
|
- |
|
realm_project
|
realm_cms
|
_RealmAdmin/login.asp in Realm CMS 2.3 and earlier allows remote attackers to bypass authentication and access admin pages via certain modified cookies, probably including (1) cUserRole, (2) cUserNam…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-2682
|
2017-09-29 10:31 |
2008-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|