|
284401
|
- |
|
boastmachine
|
boastmachine
|
SQL injection vulnerability in mail.php in boastMachine (aka bMachine) 3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2008-0422
|
2018-10-16 07:00 |
2008-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284402
|
- |
|
pacercms
|
pacercms
|
Multiple cross-site scripting (XSS) vulnerabilities in submit.php in PacerCMS before 0.6.1 allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) headline, or (3) text fi…
|
CWE-79
Cross-site Scripting
|
CVE-2008-0426
|
2018-10-16 07:00 |
2008-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284403
|
- |
|
bloo
|
bloofoxcms
|
Directory traversal vulnerability in file.php in bloofoxCMS 0.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.
|
CWE-22
Path Traversal
|
CVE-2008-0427
|
2018-10-16 07:00 |
2008-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284404
|
- |
|
bloofoxcms
|
bloofoxcms
|
Multiple SQL injection vulnerabilities in the login function in system/class_permissions.php in bloofoxCMS 0.3 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) pas…
|
CWE-89
SQL Injection
|
CVE-2008-0428
|
2018-10-16 07:00 |
2008-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284405
|
- |
|
agares_media
|
phpautovideo
|
Cross-site scripting (XSS) vulnerability in index.php in phpAutoVideo 2.21 and earlier allows remote attackers to inject arbitrary web script or HTML via the cat parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2008-0432
|
2018-10-16 07:00 |
2008-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284406
|
- |
|
agares_media
|
phpautovideo
|
PHP remote file inclusion vulnerability in theme/phpAutoVideo/LightTwoOh/sidebar.php in Agares phpAutoVideo 2.21 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the loa…
|
CWE-94
Code Injection
|
CVE-2008-0433
|
2018-10-16 07:00 |
2008-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284407
|
- |
|
gecad_technologies
|
axigen_mail_server
|
Format string vulnerability in the AXIMilter module in AXIGEN Mail Server 5.0.2 allows remote attackers to execute arbitrary code via format string specifiers in the CNHO command.
|
CWE-189
Numeric Errors
|
CVE-2008-0434
|
2018-10-16 07:00 |
2008-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284408
|
- |
|
pd9_software
|
megabbs
|
Cross-site scripting (XSS) vulnerability in profile-upload/upload.asp in PD9 Software MegaBBS 1.5.14b allows remote attackers to inject arbitrary web script or HTML via the target parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2008-0436
|
2018-10-16 07:00 |
2008-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284409
|
- |
|
novemberborn
|
sifr
|
Cross-site scripting (XSS) vulnerability in the font rendering functionality in Novemberborn sIFR 2.0.2 allows remote attackers to inject arbitrary web script or HTML via the txt parameter to a Flash…
|
CWE-79
Cross-site Scripting
|
CVE-2008-0438
|
2018-10-16 07:00 |
2008-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284410
|
- |
|
deluxebb
|
deluxebb
|
Cross-site scripting (XSS) vulnerability in templates/default/admincp/attachments_header.php in DeluxeBB 1.1 allows remote attackers to inject arbitrary web script or HTML via the lang_listofmatches …
|
CWE-79
Cross-site Scripting
|
CVE-2008-0439
|
2018-10-16 07:00 |
2008-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|