|
291491
|
- |
|
bosdev
|
bos_classifieds
|
SQL injection vulnerability in index.php in BosDev BosClassifieds allows remote attackers to execute arbitrary SQL commands via the cat_id parameter, a different vector than CVE-2008-1838.
|
CWE-89
SQL Injection
|
CVE-2008-6526
|
2017-09-29 10:33 |
2009-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291492
|
- |
|
go4i
|
go41.net_asp_forum
|
SQL injection vulnerability in forum.asp in GO4I.NET ASP Forum 1.0 allows remote attackers to execute arbitrary SQL commands via the iFor parameter.
|
CWE-89
SQL Injection
|
CVE-2008-6527
|
2017-09-29 10:33 |
2009-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291493
|
- |
|
ezonescripts
|
living_local
|
Cross-site scripting (XSS) vulnerability in listtest.php in eZoneScripts Living Local 1.1 allows remote attackers to inject arbitrary web script or HTML via the r parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2008-6529
|
2017-09-29 10:33 |
2009-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291494
|
- |
|
ezonescripts
|
living_local
|
Unrestricted file upload vulnerability in editimage.php in eZoneScripts Living Local 1.1 allows remote authenticated administrators to execute arbitrary PHP code by uploading a file with an executabl…
|
NVD-CWE-Other
|
CVE-2008-6530
|
2017-09-29 10:33 |
2009-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291495
|
- |
|
paypalestores
|
paypal_estores
|
admin/settings.php in PayPal eStores allows remote attackers to bypass intended access restrictions and change the administrative password via a direct request with a modified NewAdmin parameter.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-6535
|
2017-09-29 10:33 |
2009-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291496
|
- |
|
lightneasy
|
lightneasy
|
LightNEasy/lightneasy.php in LightNEasy No database version 1.2 allows remote attackers to obtain the hash of the administrator password via the setup "do" action to LightNEasy.php, which is cleared …
|
CWE-200
Information Exposure
|
CVE-2008-6537
|
2017-09-29 10:33 |
2009-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291497
|
- |
|
holger_schurig
|
destar
|
DeStar 0.2.2-5 allows remote attackers to add arbitrary users via a direct request to config/add/CfgOptUser.
|
CWE-20
Improper Input Validation
|
CVE-2008-6538
|
2017-09-29 10:33 |
2009-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291498
|
- |
|
holger_schurig
|
destar
|
Static code injection vulnerability in user/settings/ in DeStar 0.2.2-5 allows remote authenticated users to add arbitrary administrators and inject arbitrary Python code into destar_cfg.py via a cra…
|
CWE-94
Code Injection
|
CVE-2008-6539
|
2017-09-29 10:33 |
2009-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291499
|
- |
|
e-vision
|
e-vision_cms
|
Multiple directory traversal vulnerabilities in e-Vision CMS 2.0.2 and earlier, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via a .. (dot do…
|
CWE-22
Path Traversal
|
CVE-2008-6551
|
2017-09-29 10:33 |
2009-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291500
|
- |
|
redhat fedoraproject
|
cluster_project cman rgmanager fedora gfs2-utils
|
Red Hat Cluster Project 2.x allows local users to modify or overwrite arbitrary files via symlink attacks on files in /tmp, involving unspecified components in Resource Group Manager (aka rgmanager) …
|
CWE-59
Link Following
|
CVE-2008-6552
|
2017-09-29 10:33 |
2009-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|