|
292061
|
- |
|
modernbill
|
modernbill
|
ModernBill has changed their name to Parallels Plesk Billing. http://www.modernbill.com/
|
CWE-79
Cross-site Scripting
|
CVE-2008-5059
|
2017-09-29 10:32 |
2008-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292062
|
- |
|
modernbill
|
modernbill
|
Multiple PHP remote file inclusion vulnerabilities in ModernBill 4.4 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the DIR parameter to (1) export_batch.inc.php, (2) r…
|
CWE-94
Code Injection
|
CVE-2008-5060
|
2017-09-29 10:32 |
2008-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292063
|
- |
|
smolinari
|
mini_web_calendar
|
Cross-site scripting (XSS) vulnerability in php/cal_default.php in Mini Web Calendar (mwcal) 1.2 allows remote attackers to inject arbitrary web script or HTML via the URL.
|
CWE-79
Cross-site Scripting
|
CVE-2008-5061
|
2017-09-29 10:32 |
2008-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292064
|
- |
|
smolinari
|
mini_web_calendar
|
Directory traversal vulnerability in php/cal_pdf.php in Mini Web Calendar (mwcal) 1.2 allows remote attackers to read arbitrary files via directory traversal sequences in the thefile parameter.
|
CWE-22
Path Traversal
|
CVE-2008-5062
|
2017-09-29 10:32 |
2008-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292065
|
- |
|
otmanager
|
otmanager
|
PHP remote file inclusion vulnerability in Admin/ADM_Pagina.php in OTManager 2.4 allows remote attackers to execute arbitrary PHP code via a URL in the Tipo parameter.
|
CWE-94
Code Injection
|
CVE-2008-5063
|
2017-09-29 10:32 |
2008-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292066
|
- |
|
easy-script
|
tlguesbook
|
TlGuestBook 1.2 allows remote attackers to bypass authentication and gain administrative access by setting the tlGuestBook_login cookie to admin.
|
CWE-287
Improper Authentication
|
CVE-2008-5065
|
2017-09-29 10:32 |
2008-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292067
|
- |
|
agaresmedia
|
themesitescript
|
PHP remote file inclusion vulnerability in upload/admin/frontpage_right.php in Agares Media ThemeSiteScript 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the loadadminpage pa…
|
CWE-94
Code Injection
|
CVE-2008-5066
|
2017-09-29 10:32 |
2008-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292068
|
- |
|
pro_chat_rooms
|
pro_chat_rooms
|
SQL injection vulnerability in Pro Chat Rooms 3.0.3, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the gud parameter to (1) profiles/index.php and (…
|
CWE-89
SQL Injection
|
CVE-2008-5070
|
2017-09-29 10:32 |
2008-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292069
|
- |
|
pro_chat_rooms
|
pro_chat_rooms
|
Patch Information (login required) - http://prochatrooms.com/clients.php?cid=1
|
CWE-89
SQL Injection
|
CVE-2008-5070
|
2017-09-29 10:32 |
2008-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292070
|
- |
|
yoxel
|
yoxel
|
Multiple eval injection vulnerabilities in itpm_estimate.php in Yoxel 1.23beta and earlier allow remote authenticated users to execute arbitrary PHP code via the proj_id parameter.
|
CWE-94
Code Injection
|
CVE-2008-5071
|
2017-09-29 10:32 |
2008-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|