|
284331
|
- |
|
plutostatus
|
plutostatus_locator
|
Directory traversal vulnerability in index.php in PlutoStatus Locator 1.0 pre alpha allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter.
|
CWE-22
Path Traversal
|
CVE-2008-0819
|
2018-10-16 07:03 |
2008-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284332
|
- |
|
plutostatus
|
plutostatus_locator
|
The security focus bid link states that this is a local file include vulnerability.
|
CWE-22
Path Traversal
|
CVE-2008-0819
|
2018-10-16 07:03 |
2008-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284333
|
- |
|
scribe
|
scribe
|
Directory traversal vulnerability in index.php in Scribe 0.2 allows remote attackers to read arbitrary local files via a .. (dot dot) in the page parameter.
|
CWE-22
Path Traversal
|
CVE-2008-0822
|
2018-10-16 07:03 |
2008-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284334
|
- |
|
scribe
|
scribe
|
Security focus bid link notes that this is a local file include vulnerability.
|
CWE-22
Path Traversal
|
CVE-2008-0822
|
2018-10-16 07:03 |
2008-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284335
|
- |
|
atutor
|
atutor
|
Multiple cross-site scripting (XSS) vulnerabilities in ATutor 1.5.5 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) attributes such as style and onmouseover in (a) f…
|
CWE-79
Cross-site Scripting
|
CVE-2008-0828
|
2018-10-16 07:03 |
2008-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284336
|
- |
|
simple_cms
|
simple_cms
|
SQL injection vulnerability in indexen.php in Simple CMS 1.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the area parameter.
|
CWE-89
SQL Injection
|
CVE-2008-0835
|
2018-10-16 07:03 |
2008-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284337
|
- |
|
john_godley wordpress
|
search_unleashed search_unleashed_plugin
|
Cross-site scripting (XSS) vulnerability in the log feature in the John Godley Search Unleashed 0.2.10 plugin for WordPress allows remote attackers to inject arbitrary web script or HTML via the s pa…
|
CWE-79
Cross-site Scripting
|
CVE-2008-0837
|
2018-10-16 07:03 |
2008-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284338
|
- |
|
sophos
|
es1000 es4000
|
Multiple cross-site scripting (XSS) vulnerabilities in the web administration interface in Sophos ES1000 and ES4000 Email Security Appliance 2.1.0.0 allow remote attackers to inject arbitrary web scr…
|
CWE-79
Cross-site Scripting
|
CVE-2008-0838
|
2018-10-16 07:03 |
2008-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284339
|
- |
|
publicwarehouse
|
lightblog
|
Directory traversal vulnerability in view_member.php in Public Warehouse LightBlog 9.6 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the username paramete…
|
CWE-22
Path Traversal
|
CVE-2008-0840
|
2018-10-16 07:03 |
2008-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284340
|
- |
|
statcountex
|
statcountex
|
StatCounteX 3.0 and 3.1 allows remote attackers to obtain sensitive information and edit configuration scripts via a direct request to admin.asp.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-0843
|
2018-10-16 07:03 |
2008-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|