|
292921
|
- |
|
endonesia
|
calendar_module endonesia
|
SQL injection vulnerability in the Calendar module in eNdonesia 8.4 allows remote attackers to execute arbitrary SQL commands via the loc_id parameter in a list_events action to mod.php.
|
CWE-89
SQL Injection
|
CVE-2008-3452
|
2017-09-29 10:31 |
2008-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292922
|
- |
|
jnshosts
|
php_hosting_directory
|
JnSHosts PHP Hosting Directory 2.0 allows remote attackers to bypass authentication and gain administrative access by setting the "adm" cookie value to 1.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-3454
|
2017-09-29 10:31 |
2008-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292923
|
- |
|
jnshosts
|
php_hosting_directory
|
PHP remote file inclusion vulnerability in include/admin.php in JnSHosts PHP Hosting Directory 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the rd parameter.
|
CWE-94
Code Injection
|
CVE-2008-3455
|
2017-09-29 10:31 |
2008-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292924
|
- |
|
coppermine-gallery
|
coppermine_photo_gallery
|
themes/sample/theme.php in Coppermine Photo Gallery (CPG) 1.4.18 and earlier allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an er…
|
CWE-94
Code Injection
|
CVE-2008-3481
|
2017-09-29 10:31 |
2008-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292925
|
- |
|
coppermine-gallery
|
coppermine_photo_gallery
|
as per vendor link: http://coppermine-gallery.net/
"The development team is releasing a security update for Coppermine in order to counter a recently discovered injection vulnerability. It is import…
|
CWE-94
Code Injection
|
CVE-2008-3481
|
2017-09-29 10:31 |
2008-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292926
|
- |
|
estoreaff
|
estoreaff
|
SQL injection vulnerability in eStoreAff 0.1 allows remote attackers to execute arbitrary SQL commands via the cid parameter in a showcat action to index.php.
|
CWE-89
SQL Injection
|
CVE-2008-3484
|
2017-09-29 10:31 |
2008-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292927
|
- |
|
coppermine-gallery
|
coppermine_photo_gallery
|
Directory traversal vulnerability in the user_get_profile function in include/functions.inc.php in Coppermine Photo Gallery (CPG) 1.4.18 and earlier, when the charset is utf-8, allows remote attacker…
|
CWE-22
Path Traversal
|
CVE-2008-3486
|
2017-09-29 10:31 |
2008-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292928
|
- |
|
coppermine-gallery
|
coppermine_photo_gallery
|
http://secunia.com/advisories/31295:
"Successful exploitation requires that "Character encoding" is set to "Unicode (recommended) (utf-8)", which is the default value."
|
CWE-22
Path Traversal
|
CVE-2008-3486
|
2017-09-29 10:31 |
2008-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292929
|
- |
|
phpauctions
|
phpauction_gpl_enhanced
|
SQL injection vulnerability in profile.php in PHPAuction GPL Enhanced 2.51 allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2008-3487
|
2017-09-29 10:31 |
2008-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292930
|
- |
|
phpx
|
phpx
|
SQL injection vulnerability in checkCookie function in includes/functions.inc.php in PHPX 3.5.16 allows remote attackers to execute arbitrary SQL commands via a PXL cookie.
|
CWE-89
SQL Injection
|
CVE-2008-3489
|
2017-09-29 10:31 |
2008-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|