|
293921
|
- |
|
force10 freebsd juniper netbsd openbsd windriver
|
ftos freebsd jnos netbsd openbsd vxworks
|
The IPv6 Neighbor Discovery Protocol (NDP) implementation in (1) FreeBSD 6.3 through 7.1, (2) OpenBSD 4.2 and 4.3, (3) NetBSD, (4) Force10 FTOS before E7.7.1.1, (5) Juniper JUNOS, and (6) Wind River …
|
CWE-20
Improper Input Validation
|
CVE-2008-2476
|
2017-09-29 10:31 |
2008-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293922
|
- |
|
mx-system
|
mxbb_portal
|
SQL injection vulnerability in index.php in MxBB (aka MX-System) Portal 2.7.3 allows remote attackers to execute arbitrary SQL commands via the page parameter.
|
CWE-89
SQL Injection
|
CVE-2008-2477
|
2017-09-29 10:31 |
2008-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293923
|
- |
|
plusphp
|
plusphp_short_url_multi-user_script
|
PHP remote file inclusion vulnerability in plus.php in plusPHP Short URL Multi-User Script 1.6 allows remote attackers to execute arbitrary PHP code via a URL in the _pages_dir parameter.
|
CWE-94
Code Injection
|
CVE-2008-2480
|
2017-09-29 10:31 |
2008-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293924
|
- |
|
phpraider
|
phpraider
|
PHP remote file inclusion vulnerability in authentication/phpbb3/phpbb3.functions.php in phpRaider 1.0.7 and 1.0.7a, when register_globals is enabled, allows remote attackers to execute arbitrary PHP…
|
CWE-94
Code Injection
|
CVE-2008-2481
|
2017-09-29 10:31 |
2008-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293925
|
- |
|
xomol
|
xomol_cms
|
Directory traversal vulnerability in index.php in Xomol CMS 1.20071213 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the op parameter.
|
CWE-22
Path Traversal
|
CVE-2008-2483
|
2017-09-29 10:31 |
2008-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293926
|
- |
|
xomol
|
xomol_cms
|
SQL injection vulnerability in index.php in Xomol CMS 1.20071213, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the email parameter.
|
CWE-89
SQL Injection
|
CVE-2008-2484
|
2017-09-29 10:31 |
2008-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293927
|
- |
|
maxsite
|
maxsite
|
SQL injection vulnerability in index.php in MAXSITE 1.10 and earlier allows remote attackers to execute arbitrary SQL commands via the category parameter in a webboard action.
|
CWE-89
SQL Injection
|
CVE-2008-2487
|
2017-09-29 10:31 |
2008-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293928
|
- |
|
beaussier
|
roomphplanning
|
admin/userform.php in RoomPHPlanning 1.5 does not require administrative credentials, which allows remote authenticated users to create new admin accounts.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-2488
|
2017-09-29 10:31 |
2008-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293929
|
- |
|
quate
|
quate_cms
|
Multiple cross-site scripting (XSS) vulnerabilities in Quate CMS 0.3.4 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) index.php, (2) login.php, and (3) credits…
|
CWE-79
Cross-site Scripting
|
CVE-2008-2496
|
2017-09-29 10:31 |
2008-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293930
|
- |
|
henning_stoverud
|
phphotoalbum
|
Multiple SQL injection vulnerabilities in PHPhotoalbum 0.5 allow remote attackers to execute arbitrary SQL commands via the (1) album parameter to thumbnails.php and the (2) pid parameter to displayi…
|
CWE-89
SQL Injection
|
CVE-2008-2501
|
2017-09-29 10:31 |
2008-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|