|
292601
|
- |
|
southrivertech
|
titan_ftp_server
|
Titan FTP Server 6.26 build 630 allows remote attackers to cause a denial of service (CPU consumption) via the SITE WHO command.
|
CWE-399
Resource Management Errors
|
CVE-2008-6082
|
2017-09-29 10:32 |
2009-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292602
|
- |
|
.matteoiammarrone
|
iamma_simple_gallery
|
Unrestricted file upload vulnerability in pages/download.php in Iamma Simple Gallery 1.0 and 2.0 allows remote attackers to execute arbitrary PHP code by uploading a file with an executable extension…
|
CWE-20
Improper Input Validation
|
CVE-2008-6084
|
2017-09-29 10:32 |
2009-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292603
|
- |
|
camera_life
|
camera_life
|
SQL injection vulnerability in album.php in Camera Life 2.6.2b4 allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2008-3355.
|
CWE-89
SQL Injection
|
CVE-2008-6086
|
2017-09-29 10:32 |
2009-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292604
|
- |
|
camera_life
|
camera_life
|
Cross-site scripting (XSS) vulnerability in topic.php in Camera Life 2.6.2b4 allows remote attackers to inject arbitrary web script or HTML via the name parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2008-6087
|
2017-09-29 10:32 |
2009-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292605
|
- |
|
joomtracker
|
com_joomtracker
|
SQL injection vulnerability in the Joomtracker (com_joomtracker) 1.01 module for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a tordetails action to index…
|
CWE-89
SQL Injection
|
CVE-2008-6088
|
2017-09-29 10:32 |
2009-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292606
|
- |
|
scriptsez
|
easy_image_downloader
|
Directory traversal vulnerability in main.php in ScriptsEz Easy Image Downloader allows remote attackers to read arbitrary files via a .. (dot dot) in the id parameter in a download action.
|
CWE-22
Path Traversal
|
CVE-2008-6089
|
2017-09-29 10:32 |
2009-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292607
|
- |
|
scriptsez
|
mini_hosting_panel
|
Directory traversal vulnerability in members.php in ScriptsEz Mini Hosting Panel allows remote attackers to read arbitrary local files via a .. (dot dot) in the dir parameter in a view action.
|
CWE-22
Path Traversal
|
CVE-2008-6090
|
2017-09-29 10:32 |
2009-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292608
|
- |
|
bmforum
|
bmforum
|
SQL injection vulnerability in plugins.php in BMForum 5.6, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the tagname parameter.
|
CWE-89
SQL Injection
|
CVE-2008-6091
|
2017-09-29 10:32 |
2009-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292609
|
- |
|
phpscripts
|
ranking-script
|
phpscripts Ranking Script allows remote attackers to bypass authentication and gain administrative access by sending an admin=ja cookie.
|
CWE-287
Improper Authentication
|
CVE-2008-6092
|
2017-09-29 10:32 |
2009-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292610
|
- |
|
noname-cms
|
noname_cms
|
SQL injection vulnerability in index.php in Noname CMS 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the (1) file_id parameter in a detailansic…
|
CWE-89
SQL Injection
|
CVE-2008-6093
|
2017-09-29 10:32 |
2009-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|