|
292271
|
- |
|
videoscript
|
videoscript
|
The password change feature (admin/cp.php) in VideoScript 4.0.1.50 and earlier does not check for administrative authentication and does not require knowledge of the original password, which allows r…
|
CWE-287
Improper Authentication
|
CVE-2008-5219
|
2017-09-29 10:32 |
2008-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292272
|
- |
|
wportfolio
|
wportfolio
|
Unrestricted file upload vulnerability in admin/upload_form.php in wPortfolio 0.3 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then …
|
CWE-20
Improper Input Validation
|
CVE-2008-5220
|
2017-09-29 10:32 |
2008-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292273
|
- |
|
wportfolio
|
wportfolio
|
The account_save action in admin/userinfo.php in wPortfolio 0.3 and earlier does not require authentication and does not require knowledge of the original password, which allows remote attackers to c…
|
CWE-287
Improper Authentication
|
CVE-2008-5221
|
2017-09-29 10:32 |
2008-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292274
|
- |
|
airvae
|
commerce
|
SQL injection vulnerability in index.php in Airvae Commerce 3.0 allows remote attackers to execute arbitrary SQL commands via the pid parameter.
|
CWE-89
SQL Injection
|
CVE-2008-5223
|
2017-09-29 10:32 |
2008-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292275
|
- |
|
mambads mambo
|
mambads mambo
|
SQL injection vulnerability in the MambAds (com_mambads) component 1.0 RC1 Beta and 1.0 RC1 for Mambo allows remote attackers to execute arbitrary SQL commands via the ma_cat parameter in a view acti…
|
CWE-89
SQL Injection
|
CVE-2008-5226
|
2017-09-29 10:32 |
2008-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292276
|
- |
|
tntforum
|
tnt_forum
|
Directory traversal vulnerability in index.php in TNT Forum 0.9.4, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequ…
|
CWE-22
Path Traversal
|
CVE-2008-5265
|
2017-09-29 10:32 |
2008-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292277
|
- |
|
experts
|
experts
|
SQL injection vulnerability in answer.php in Experts 1.0.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the question_id parameter.
|
CWE-89
SQL Injection
|
CVE-2008-5267
|
2017-09-29 10:32 |
2008-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292278
|
- |
|
powie
|
psys
|
SQL injection vulnerability in index.php in pSys 0.7.0 alpha allows remote attackers to execute arbitrary SQL commands via the shownews parameter.
|
CWE-89
SQL Injection
|
CVE-2008-5269
|
2017-09-29 10:32 |
2008-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292279
|
- |
|
wareziz
|
yuhhu_superstar_2008
|
SQL injection vulnerability in view.topics.php in Yuhhu Superstar 2008 allows remote attackers to execute arbitrary SQL commands via the board parameter.
|
CWE-89
SQL Injection
|
CVE-2008-5270
|
2017-09-29 10:32 |
2008-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292280
|
- |
|
syndeocms
|
syndeocms
|
Multiple directory traversal vulnerabilities in Fred Stuurman SyndeoCMS 2.6.0 allow remote authenticated users to read arbitrary files via a .. (dot dot) in the template parameter to (1) starnet/edit…
|
CWE-22
Path Traversal
|
CVE-2008-5272
|
2017-09-29 10:32 |
2008-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|