|
293121
|
- |
|
evilsentinel
|
evilsentinel
|
admin/index.php in Evilsentinel 1.0.9 and earlier sends a redirect to the web browser but does not exit, which allows remote attackers to gain administrative privileges and make arbitrary configurati…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-0350
|
2017-09-29 10:30 |
2008-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293122
|
- |
|
evilsentinel
|
evilsentinel
|
admin/config.php in Evilsentinel 1.0.9 and earlier allows remote attackers to bypass the CAPTCHA test by omitting the es_security_captcha parameter and not invoking captcha.php.
|
CWE-287
Improper Authentication
|
CVE-2008-0351
|
2017-09-29 10:30 |
2008-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293123
|
- |
|
linux
|
linux_kernel
|
The Linux kernel 2.6.20 through 2.6.21.1 allows remote attackers to cause a denial of service (panic) via a certain IPv6 packet, possibly involving the Jumbo Payload hop-by-hop option (jumbogram).
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2008-0352
|
2017-09-29 10:30 |
2008-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293124
|
- |
|
php-residence
|
php-residence
|
SQL injection vulnerability in visualizza_tabelle.php in php-residence 0.7.2 and 1.0 allows remote attackers to execute arbitrary SQL commands via the cognome_cerca parameter. NOTE: some of these de…
|
CWE-89
SQL Injection
|
CVE-2008-0353
|
2017-09-29 10:30 |
2008-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293125
|
- |
|
phpecho_cms
|
phpecho_cms
|
SQL injection vulnerability in index.php in the forum module in PHPEcho CMS, probably 2.0-rc3 and earlier, allows remote attackers to execute arbitrary SQL commands via the id parameter in a section …
|
CWE-89
SQL Injection
|
CVE-2008-0355
|
2017-09-29 10:30 |
2008-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293126
|
- |
|
galaxyscripts
|
mini_file_host
|
Directory traversal vulnerability in pages/upload.php in Galaxyscripts Mini File Host 1.2.1 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal se…
|
CWE-22
Path Traversal
|
CVE-2008-0357
|
2017-09-29 10:30 |
2008-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293127
|
- |
|
pixelpost
|
pixelpost
|
SQL injection vulnerability in index.php in Pixelpost 1.7 allows remote attackers to execute arbitrary SQL commands via the parent_id parameter.
|
CWE-89
SQL Injection
|
CVE-2008-0358
|
2017-09-29 10:30 |
2008-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293128
|
- |
|
alilg
|
alitalk
|
Multiple SQL injection vulnerabilities in aliTalk 1.9.1.1, when magic_quotes_gpc is disabled, allow remote authenticated users to execute arbitrary SQL commands via (1) the mohit parameter to (a) inc…
|
CWE-89
SQL Injection
|
CVE-2008-0371
|
2017-09-29 10:30 |
2008-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293129
|
- |
|
softpedia
|
small_axe_weblog
|
PHP remote file inclusion vulnerability in inc/linkbar.php in Small Axe Weblog 0.3.1 allows remote attackers to execute arbitrary PHP code via a URL in the cfile parameter.
|
CWE-94
Code Injection
|
CVE-2008-0376
|
2017-09-29 10:30 |
2008-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293130
|
- |
|
digital_data_communications
|
rtspvapgdecoder.dll
|
Buffer overflow in the Digital Data Communications RtspVaPgCtrl ActiveX control (RtspVapgDecoder.dll 1.1.0.29) allows remote attackers to execute arbitrary code via a long MP4Prefix property.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2008-0380
|
2017-09-29 10:30 |
2008-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|