|
292831
|
- |
|
erocms
|
erocms
|
SQL injection vulnerability in index.php in eroCMS 1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the site parameter.
|
CWE-89
SQL Injection
|
CVE-2008-2792
|
2017-09-29 10:31 |
2008-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292832
|
- |
|
clip-share
|
clipshare
|
SQL injection vulnerability in group_posts.php in ClipShare before 3.0.1 allows remote attackers to execute arbitrary SQL commands via the tid parameter.
|
CWE-89
SQL Injection
|
CVE-2008-2793
|
2017-09-29 10:31 |
2008-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292833
|
- |
|
freecms.us
|
freecms
|
SQL injection vulnerability in index.php in FreeCMS 0.2 allows remote attackers to execute arbitrary SQL commands via the page parameter.
|
CWE-89
SQL Injection
|
CVE-2008-2796
|
2017-09-29 10:31 |
2008-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292834
|
- |
|
shoutcastadmin
|
wallcity-server_shoutcast_admin_panel
|
Directory traversal vulnerability in index.php in WallCity-Server Shoutcast Admin Panel 2.0, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files vi…
|
CWE-22
Path Traversal
|
CVE-2008-2813
|
2017-09-29 10:31 |
2008-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292835
|
- |
|
o2php
|
oxygen
|
SQL injection vulnerability in post.php in Oxygen (aka O2PHP Bulletin Board) 2.0 allows remote attackers to execute arbitrary SQL commands via the repquote parameter in a reply action, a different ve…
|
CWE-89
SQL Injection
|
CVE-2008-2816
|
2017-09-29 10:31 |
2008-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292836
|
- |
|
nitropowered
|
nitro_web_gallery
|
SQL injection vulnerability in albums.php in NiTrO Web Gallery 1.4.3 and earlier allows remote attackers to execute arbitrary SQL commands via the CatId parameter in a show action.
|
CWE-89
SQL Injection
|
CVE-2008-2817
|
2017-09-29 10:31 |
2008-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292837
|
- |
|
easy-clanpage
|
easy-clanpage
|
Directory traversal vulnerability in Easy-Clanpage 3.0 b1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the section parameter to the default URI.
|
CWE-22
Path Traversal
|
CVE-2008-2818
|
2017-09-29 10:31 |
2008-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292838
|
- |
|
phpeasynews
|
phpeasyblog
|
SQL injection vulnerability in newsarchive.php in PHPeasyblog (formerly phpeasynews) 1.13 RC2 and earlier allows remote attackers to execute arbitrary SQL commands via the post parameter.
|
CWE-89
SQL Injection
|
CVE-2008-2823
|
2017-09-29 10:31 |
2008-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292839
|
- |
|
fullrevolution
|
aspwebcalendar2008
|
Unrestricted file upload vulnerability in calendar_admin.asp in Full Revolution aspWebCalendar 2008 allows remote attackers to upload and execute arbitrary code via the FILE1 parameter in an uploadfi…
|
CWE-94
Code Injection
|
CVE-2008-2832
|
2017-09-29 10:31 |
2008-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292840
|
- |
|
worldlevel
|
le.cms
|
admin/upload.php in le.cms 1.4 and earlier allows remote attackers to bypass administrative authentication, and upload and execute arbitrary files in images/, via a nonzero value for the submit0 para…
|
CWE-287
Improper Authentication
|
CVE-2008-2833
|
2017-09-29 10:31 |
2008-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|