|
292821
|
- |
|
activewebsoftwares
|
quick_tree_view_.net
|
Quick Tree View .NET 3.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request to qtv.mdb.
|
CWE-200
Information Exposure
|
CVE-2008-6387
|
2017-09-29 10:33 |
2009-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292822
|
- |
|
4u2ges
|
rapid_classified
|
Rapid Classified 3.1 and 3.15 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request to cld…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-6388
|
2017-09-29 10:33 |
2009-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292823
|
- |
|
aliensoftcorp
|
rae_media_contact_management
|
SQL injection vulnerability in asadmin/default.asp in Rae Media Contact Management Software SOHO, Standard, and Enterprise allows remote attackers to execute arbitrary SQL commands via the Password p…
|
CWE-89
SQL Injection
|
CVE-2008-6389
|
2017-09-29 10:33 |
2009-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292824
|
- |
|
ocean12tech
|
membership_manager_pro
|
SQL injection vulnerability in login.asp in Ocean12 Membership Manager Pro allows remote attackers to execute arbitrary SQL commands via the Password parameter. NOTE: the provenance of this informat…
|
CWE-89
SQL Injection
|
CVE-2008-6390
|
2017-09-29 10:33 |
2009-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292825
|
- |
|
psi-im
|
psi
|
PSI Jabber client before 0.12.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a file transfer request with a negative value in a SOCKS5 option, …
|
CWE-189
Numeric Errors
|
CVE-2008-6393
|
2017-09-29 10:33 |
2009-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292826
|
- |
|
jetik
|
jetik-web
|
SQL injection vulnerability in sayfa.php in JETIK-WEB allows remote attackers to execute arbitrary SQL commands via the kat parameter.
|
CWE-89
SQL Injection
|
CVE-2008-6401
|
2017-09-29 10:33 |
2009-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292827
|
- |
|
muskatli
|
sofi_webgui
|
PHP remote file inclusion vulnerability in hu/modules/reg-new/modstart.php in Sofi WebGui 0.6.3 PRE and earlier allows remote attackers to execute arbitrary PHP code via a URL in the mod_dir paramete…
|
CWE-94
Code Injection
|
CVE-2008-6402
|
2017-09-29 10:33 |
2009-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292828
|
- |
|
openrat
|
openrat
|
PHP remote file inclusion vulnerability in themes/default/include/html/insert.inc.php in OpenRat 0.8-beta4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the tpl_dir p…
|
CWE-94
Code Injection
|
CVE-2008-6403
|
2017-09-29 10:33 |
2009-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292829
|
- |
|
greatclone
|
hotscripts_clone
|
SQL injection vulnerability in showcategory.php in Hotscripts Clone allows remote attackers to execute arbitrary SQL commands via the cid parameter.
|
CWE-89
SQL Injection
|
CVE-2008-6405
|
2017-09-29 10:33 |
2009-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292830
|
- |
|
brian_wilson
|
ol\'bookmarks
|
Directory traversal vulnerability in frame.php in ol'bookmarks manager 0.7.5 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the framefile parameter.
|
CWE-22
Path Traversal
|
CVE-2008-6407
|
2017-09-29 10:33 |
2009-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|