|
297791
|
- |
|
geertsen_holdings_inc
|
geecarts
|
Multiple PHP remote file inclusion vulnerabilities in GeeCarts allow remote attackers to execute arbitrary PHP code via a URL in the id parameter to (1) show.php, (2) search.php, and (3) view.php. N…
|
CWE-94
Code Injection
|
CVE-2008-1622
|
2017-08-8 10:30 |
2008-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
297792
|
- |
|
eggblog
|
eggblog
|
SQL injection vulnerability in eggBlog before 4.0.1 allows remote attackers to execute arbitrary SQL commands via an unspecified cookie. NOTE: this might overlap CVE-2008-0159.
|
CWE-89 CWE-20
SQL Injection Improper Input Validation
|
CVE-2008-1626
|
2017-08-8 10:30 |
2008-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
297793
|
- |
|
cds_software_consortium
|
invenio
|
CDS Invenio 0.92.1 and earlier allows remote authenticated users to delete email notification alerts of arbitrary users via a modified internal UID.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-1627
|
2017-08-8 10:30 |
2008-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
297794
|
- |
|
linux
|
audit
|
Stack-based buffer overflow in the audit_log_user_command function in lib/audit_logging.c in Linux Audit before 1.7 might allow remote attackers to execute arbitrary code via a long command argument.…
|
CWE-264 CWE-119
Permissions, Privileges, and Access Controls Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2008-1628
|
2017-08-8 10:30 |
2008-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
297795
|
- |
|
linux
|
audit
|
Additional information can be found at:
http://www.securityfocus.com/bid/28524/info
http://www.frsirt.com/english/advisories/2008/1052
|
CWE-264 CWE-119
Permissions, Privileges, and Access Controls Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2008-1628
|
2017-08-8 10:30 |
2008-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
297796
|
- |
|
pau_rodriguez
|
phpkrm
|
Cross-site scripting (XSS) vulnerability in PHPkrm before 1.5.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2008-1629
|
2017-08-8 10:30 |
2008-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
297797
|
- |
|
pau_rodriguez
|
phpkrm
|
Additional information can be found at:
http://www.securityfocus.com/bid/28510
|
CWE-79
Cross-site Scripting
|
CVE-2008-1629
|
2017-08-8 10:30 |
2008-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
297798
|
- |
|
emedia_office_gmbh
|
cuteflow
|
Multiple SQL injection vulnerabilities in CuteFlow 2.10.0 allow remote authenticated users to execute arbitrary SQL commands via the (1) listid parameter to pages/editmailinglist_step1.php, the (2) u…
|
CWE-89
SQL Injection
|
CVE-2008-1632
|
2017-08-8 10:30 |
2008-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
297799
|
- |
|
emedia_office_gmbh
|
cuteflow
|
Addtional information can be found at:
http://xforce.iss.net/xforce/xfdb/41537
|
CWE-89
SQL Injection
|
CVE-2008-1632
|
2017-08-8 10:30 |
2008-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
297800
|
- |
|
mondo
|
rescue
|
Unspecified vulnerability in Mondo Rescue before 2.2.5 has unknown impact and attack vectors, related to the use of (1) /tmp and (2) MINDI_CACHE.
|
NVD-CWE-noinfo
|
CVE-2008-1633
|
2017-08-8 10:30 |
2008-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|