|
291441
|
- |
|
myphpindexer
|
my_php_indexer
|
Multiple directory traversal vulnerabilities in index.php in My PHP Indexer 1.0 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) d and (2) f parameters.
|
CWE-22
Path Traversal
|
CVE-2008-6183
|
2017-09-29 10:33 |
2009-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291442
|
- |
|
medialab-karlsruhe
|
ownbiblio
|
SQL injection vulnerability in the OwnBiblio (com_ownbiblio) component 1.5.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a catalogue action to ind…
|
CWE-89
SQL Injection
|
CVE-2008-6184
|
2017-09-29 10:33 |
2009-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291443
|
- |
|
noticeware
|
noticeware_email_server_ng
|
NoticeWare Email Server NG 5.1.2.2 allows remote attackers to cause a denial of service (crash) via multiple POP3 requests with a long PASS command.
|
CWE-20
Improper Input Validation
|
CVE-2008-6185
|
2017-09-29 10:33 |
2009-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291444
|
- |
|
raidenftpd
|
raidenftpd
|
Stack-based buffer overflow in RaidenFTPD 2.4 build 3620 allows remote authenticated users to cause a denial of service (crash) or execute arbitrary code via long (1) CWD and (2) MLST commands.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2008-6186
|
2017-09-29 10:33 |
2009-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291445
|
- |
|
myblog
|
myblog
|
Sam Crew MyBlog stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain sensitive information.
|
CWE-310
Cryptographic Issues
|
CVE-2008-6193
|
2017-09-29 10:33 |
2009-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291446
|
- |
|
kwsphp
|
galerie_module
|
SQL injection vulnerability in index.php in the galerie module for KwsPHP 1.3.456 allows remote attackers to execute arbitrary SQL commands via the id_gal parameter in a gal action.
|
CWE-89
SQL Injection
|
CVE-2008-6197
|
2017-09-29 10:33 |
2009-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291447
|
- |
|
mybboard
|
custom_pages_plugin
|
SQL injection vulnerability in pages.php in Custom Pages 1.0 plugin for MyBulletinBoard (MyBB) allows remote attackers to execute arbitrary SQL commands via the page parameter.
|
CWE-89
SQL Injection
|
CVE-2008-6198
|
2017-09-29 10:33 |
2009-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291448
|
- |
|
2532gigs
|
2532gigs
|
2532designs 2532|Gigs 1.2.2 and earlier allows remote attackers to trigger a backup and obtain sensitive information via a direct request to backup.php, which creates backup.sql under the web root wi…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-6199
|
2017-09-29 10:33 |
2009-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291449
|
- |
|
2532gigs
|
2532gigs
|
Reference links indicate attacker must be authenticated for attack to be successful.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-6199
|
2017-09-29 10:33 |
2009-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291450
|
- |
|
jakob-persson
|
cobalt
|
SQL injection vulnerability in CoBaLT 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter to (1) urun.asp, (2) admin/bayi_listele.asp, (3) admin/urun_grup_listele.asp, …
|
CWE-89
SQL Injection
|
CVE-2008-6202
|
2017-09-29 10:33 |
2009-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|