|
292791
|
- |
|
mebiblio
|
mebiblio
|
Unrestricted file upload vulnerability in upload/uploader.html in meBiblio 0.4.7 allows remote attackers to execute arbitrary code by uploading a .php file, then accessing it via a direct request to …
|
CWE-20
Improper Input Validation
|
CVE-2008-2648
|
2017-09-29 10:31 |
2008-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292792
|
- |
|
don3
|
desktoponnet
|
Multiple PHP remote file inclusion vulnerabilities in DesktopOnNet 3 Beta allow remote attackers to execute arbitrary PHP code via a URL in the app_path parameter to (1) don3_requiem.don3app/don3_req…
|
CWE-94
Code Injection
|
CVE-2008-2649
|
2017-09-29 10:31 |
2008-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292793
|
- |
|
cmsimple
|
cmsimple
|
Directory traversal vulnerability in cmsimple/cms.php in CMSimple 3.1, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the…
|
CWE-22
Path Traversal
|
CVE-2008-2650
|
2017-09-29 10:31 |
2008-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292794
|
- |
|
cmsimple
|
cmsimple
|
Upgrade requires login when downloads link is clicked from X-Force site.
|
CWE-22
Path Traversal
|
CVE-2008-2650
|
2017-09-29 10:31 |
2008-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292795
|
- |
|
joomla
|
com_joobb
|
SQL injection vulnerability in the Joomla! Bulletin Board (aka Joo!BB or com_joobb) component 0.5.9 for Joomla! allows remote attackers to execute arbitrary SQL commands via the forum parameter in a …
|
CWE-89
SQL Injection
|
CVE-2008-2651
|
2017-09-29 10:31 |
2008-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292796
|
- |
|
powie
|
pnews
|
SQL injection vulnerability in index.php in Powie pNews 2.08 and 2.10, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the shownews parameter.
|
CWE-89
SQL Injection
|
CVE-2008-2673
|
2017-09-29 10:31 |
2008-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292797
|
- |
|
joomla
|
com_news_portal joomla
|
SQL injection vulnerability in the iJoomla News Portal (com_news_portal) component 1.0 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter to in…
|
CWE-89
SQL Injection
|
CVE-2008-2676
|
2017-09-29 10:31 |
2008-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292798
|
- |
|
telephone
|
telephone_directory_2008
|
Cross-site scripting (XSS) vulnerability in edit1.php in Telephone Directory 2008 allows remote attackers to inject arbitrary web script or HTML via the action parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2008-2677
|
2017-09-29 10:31 |
2008-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292799
|
- |
|
telephone
|
telephone_directory_2008
|
Multiple SQL injection vulnerabilities in Telephone Directory 2008, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) code parameter in a confirm…
|
CWE-89
SQL Injection
|
CVE-2008-2678
|
2017-09-29 10:31 |
2008-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292800
|
- |
|
realm_project
|
realm_cms
|
SQL injection vulnerability in the KeyWordsList function in _includes/inc_routines.asp in Realm CMS 2.3 and earlier allows remote attackers to execute arbitrary SQL commands via the kwrd parameter in…
|
CWE-89
SQL Injection
|
CVE-2008-2679
|
2017-09-29 10:31 |
2008-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|