|
291621
|
- |
|
pluck-cms
|
pluck
|
Directory traversal vulnerability in data/modules/blog/module_pages_site.php in Pluck 4.6.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the post paramet…
|
CWE-22
Path Traversal
|
CVE-2008-6842
|
2017-09-29 10:33 |
2009-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291622
|
- |
|
ez
|
ez_publish
|
The registration view (/user/register) in eZ Publish 3.5.6 and earlier, and possibly other versions before 3.9.5, 3.10.1, and 4.0.1, allows remote attackers to gain privileges as other users via modi…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-6844
|
2017-09-29 10:33 |
2009-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291623
|
- |
|
w2b
|
phpgreetcards
|
Cross-site scripting (XSS) vulnerability in index.php in phpGreetCards 3.7 allows remote attackers to inject arbitrary web script or HTML via the category parameter in a select action.
|
CWE-79
Cross-site Scripting
|
CVE-2008-6848
|
2017-09-29 10:33 |
2009-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291624
|
- |
|
w2b
|
phpgreetcards
|
Unrestricted file upload vulnerability in index.php in phpGreetCards 3.7 allows remote attackers to execute arbitrary PHP code by uploading a file with an executable extension, then accessing it via …
|
CWE-94
Code Injection
|
CVE-2008-6849
|
2017-09-29 10:33 |
2009-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291625
|
- |
|
php_link_directory
|
php_link_directory
|
SQL injection vulnerability in page.php in PHP Link Directory (phpLD) 3.3, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands…
|
CWE-89
SQL Injection
|
CVE-2008-6851
|
2017-09-29 10:33 |
2009-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291626
|
- |
|
joomla markus_donhauser
|
joomla\! ice_gallery_component_for_joomla
|
SQL injection vulnerability in the Ice Gallery (com_ice) component 0.5 beta 2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php.
|
CWE-89
SQL Injection
|
CVE-2008-6852
|
2017-09-29 10:33 |
2009-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291627
|
- |
|
netcat
|
netcat
|
SQL injection vulnerability in modules/poll/index.php in AIST NetCat 3.0 and 3.12 allows remote attackers to execute arbitrary SQL commands via the PollID parameter.
|
CWE-89
SQL Injection
|
CVE-2008-6853
|
2017-09-29 10:33 |
2009-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291628
|
- |
|
xigla
|
absolute_faq_manager_.net
|
Xigla Software Absolute FAQ Manager.NET 6.0 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.
|
CWE-287
Improper Authentication
|
CVE-2008-6854
|
2017-09-29 10:33 |
2009-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291629
|
- |
|
xigla
|
absolute_news_feed
|
Xigla Software Absolute News Feed 1.0 and possibly 1.5 allows remote attackers to bypass authentication and gain administrative access by setting a certain cookie.
|
CWE-287
Improper Authentication
|
CVE-2008-6855
|
2017-09-29 10:33 |
2009-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291630
|
- |
|
xigla
|
absolute_news_manager.net
|
Xigla Software Absolute News Manager.NET 5.1 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.
|
CWE-287
Improper Authentication
|
CVE-2008-6856
|
2017-09-29 10:33 |
2009-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|