|
292261
|
- |
|
joomla
|
com_datsogallery
|
SQL injection vulnerability in sub_votepic.php in the Datsogallery (com_datsogallery) module 1.6 for Joomla! allows remote attackers to execute arbitrary SQL commands via the User-Agent HTTP header.
|
CWE-89
SQL Injection
|
CVE-2008-5208
|
2017-09-29 10:32 |
2008-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292262
|
- |
|
admidio
|
admidio
|
Directory traversal vulnerability in modules/download/get_file.php in Admidio 1.4.8 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.
|
CWE-22
Path Traversal
|
CVE-2008-5209
|
2017-09-29 10:32 |
2008-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292263
|
- |
|
phpblock
|
phpblock
|
Multiple PHP remote file inclusion vulnerabilities in PhpBlock A8.5 allow remote attackers to execute arbitrary PHP code via a URL in the PATH_TO_CODE parameter to (1) script/init/createallimagecache…
|
CWE-94
Code Injection
|
CVE-2008-5210
|
2017-09-29 10:32 |
2008-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292264
|
- |
|
aj_square
|
aj_auction
|
SQL injection vulnerability in classifide_ad.php in AJ Auction 6.2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the item_id parameter.
|
CWE-89
SQL Injection
|
CVE-2008-5212
|
2017-09-29 10:32 |
2008-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292265
|
- |
|
aj_square
|
aj_article
|
SQL injection vulnerability in featured_article.php in AJ Article 1.0 allows remote attackers to execute arbitrary SQL commands via the artid parameter in a search detail action.
|
CWE-89
SQL Injection
|
CVE-2008-5213
|
2017-09-29 10:32 |
2008-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292266
|
- |
|
clanlite
|
clanlite
|
Cross-site scripting (XSS) vulnerability in service/calendrier.php in ClanLite 2.2006.05.20 allows remote attackers to inject arbitrary web script or HTML via the annee parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2008-5214
|
2017-09-29 10:32 |
2008-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292267
|
- |
|
clanlite
|
clanlite
|
SQL injection vulnerability in service/profil.php in ClanLite 2.2006.05.20 allows remote attackers to execute arbitrary SQL commands via the link parameter.
|
CWE-89
SQL Injection
|
CVE-2008-5215
|
2017-09-29 10:32 |
2008-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292268
|
- |
|
aj_square
|
zeuscart
|
SQL injection vulnerability in category_list.php in AJ Square ZeusCart 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter.
|
CWE-89
SQL Injection
|
CVE-2008-5216
|
2017-09-29 10:32 |
2008-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292269
|
- |
|
phpc0d3r
|
txtcms
|
Directory traversal vulnerability in index.php in txtCMS 0.3, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files v…
|
CWE-22
Path Traversal
|
CVE-2008-5217
|
2017-09-29 10:32 |
2008-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292270
|
- |
|
scriptsez
|
freeze_greetings
|
ScriptsEz FREEze Greetings 1.0 stores pwd.txt under the web root with insufficient access control, which allows remote attackers to obtain cleartext passwords.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-5218
|
2017-09-29 10:32 |
2008-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|