|
291481
|
- |
|
quadcomm
|
q-shop
|
Cross-site scripting (XSS) vulnerability in search.asp in QuadComm Q-Shop 3.0, and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via the srkeys parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2008-6259
|
2017-09-29 10:33 |
2009-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291482
|
- |
|
ultrastats
|
ultrastats
|
SQL injection vulnerability in index.php in Ultrastats 0.2.144 and 0.3.11 allows remote attackers to execute arbitrary SQL commands via the serverid parameter.
|
CWE-89
SQL Injection
|
CVE-2008-6260
|
2017-09-29 10:33 |
2009-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291483
|
- |
|
e-topbiz
|
admanager
|
SQL injection vulnerability in view.php in E-topbiz AdManager 4 allows remote attackers to execute arbitrary SQL commands via the group parameter.
|
CWE-89
SQL Injection
|
CVE-2008-6261
|
2017-09-29 10:33 |
2009-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291484
|
- |
|
infireal
|
saturncms
|
SQL injection vulnerability in lib/user/t_user.php in SaturnCMS allows remote attackers to execute arbitrary SQL commands via the username parameter to the _userLoggedIn function. NOTE: some of thes…
|
CWE-89
SQL Injection
|
CVE-2008-6263
|
2017-09-29 10:33 |
2009-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291485
|
- |
|
e-topbiz
|
slide_popups
|
SQL injection vulnerability in admin/admin.php in E-topbiz Slide Popups 1.0 allows remote attackers to execute arbitrary SQL commands via the password parameter.
|
CWE-89
SQL Injection
|
CVE-2008-6264
|
2017-09-29 10:33 |
2009-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291486
|
- |
|
cyberfolio
|
cyberfolio
|
Directory traversal vulnerability in portfolio/css.php in Cyberfolio 7.12.2 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the theme parameter.
|
CWE-22
Path Traversal
|
CVE-2008-6265
|
2017-09-29 10:33 |
2009-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291487
|
- |
|
sadi_samami
|
multi_languages_webshop_online
|
Cross-site scripting (XSS) vulnerability in detail.php in Multi Languages WebShop Online 1.02 allows remote attackers to inject arbitrary web script or HTML via the name parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2008-6267
|
2017-09-29 10:33 |
2009-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291488
|
- |
|
sadi_samami
|
multi_languages_webshop_online
|
SQL injection vulnerability in detail.php in WEBBDOMAIN Multi Languages WebShop Online 1.02 allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2008-6268
|
2017-09-29 10:33 |
2009-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291489
|
- |
|
joovili
|
joovili
|
Joovili 3.1.4 allows remote attackers to bypass authentication and gain privileges as other users, including the administrator, by setting the (1) session_id, session_logged_in, and session_username …
|
CWE-287
Improper Authentication
|
CVE-2008-6269
|
2017-09-29 10:33 |
2009-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291490
|
- |
|
miticdjd
|
apoll
|
SQL injection vulnerability in admin/index.php in Dragan Mitic Apoll 0.7 beta and 0.7.5 allows remote attackers to execute arbitrary SQL command via the user parameter.
|
CWE-89
SQL Injection
|
CVE-2008-6270
|
2017-09-29 10:33 |
2009-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|