|
292301
|
- |
|
e107
|
e107
|
SQL injection vulnerability in usersettings.php in e107 0.7.13 and earlier allows remote authenticated users to execute arbitrary SQL commands via the ue[] parameter.
|
CWE-89
SQL Injection
|
CVE-2008-5320
|
2017-09-29 10:32 |
2008-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292302
|
- |
|
xoops_hocasi
|
gesgaleri
|
SQL injection vulnerability in index.php in GesGaleri, a module for XOOPS, allows remote attackers to execute arbitrary SQL commands via the no parameter.
|
CWE-89
SQL Injection
|
CVE-2008-5321
|
2017-09-29 10:32 |
2008-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292303
|
- |
|
easy-script
|
wysi_wiki_wyg
|
Wysi Wiki Wyg 1.0 allows remote attackers to obtain system information via an invalid categup parameter to index.php, which calls the phpinfo function.
|
CWE-200
Information Exposure
|
CVE-2008-5322
|
2017-09-29 10:32 |
2008-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292304
|
- |
|
easy-script
|
wysi_wiki_wyg
|
Cross-site scripting (XSS) vulnerability in index.php in Wysi Wiki Wyg 1.0 allows remote attackers to inject arbitrary web script or HTML via the s parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2008-5323
|
2017-09-29 10:32 |
2008-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292305
|
- |
|
pie
|
pie
|
Multiple PHP remote file inclusion vulnerabilities in Pie 0.5.3 allow remote attackers to execute arbitrary PHP code via a URL in the (1) lib parameter to files in lib/action/ including (a) alias.php…
|
CWE-94
Code Injection
|
CVE-2008-5332
|
2017-09-29 10:32 |
2008-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292306
|
- |
|
nitrotech
|
nitrotech
|
SQL injection vulnerability in members.php in NitroTech 0.0.3a allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2008-5333
|
2017-09-29 10:32 |
2008-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292307
|
- |
|
nitrotech
|
nitrotech
|
PHP remote file inclusion vulnerability in includes/common.php in NitroTech 0.0.3a allows remote attackers to execute arbitrary PHP code via a URL in the root parameter.
|
CWE-94
Code Injection
|
CVE-2008-5334
|
2017-09-29 10:32 |
2008-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292308
|
- |
|
php-fusion
|
php-fusion
|
SQL injection vulnerability in messages.php in PHP-Fusion 6.01.15 and 7.00.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the subject and msg_send…
|
CWE-89
SQL Injection
|
CVE-2008-5335
|
2017-09-29 10:32 |
2008-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292309
|
- |
|
multimania
|
bandsite_portal_system bandwebsite
|
SQL injection vulnerability in lyrics.php in Bandwebsite (aka Bandsite portal system) 1.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2008-5337
|
2017-09-29 10:32 |
2008-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292310
|
- |
|
multimania
|
bandsite_portal_system bandwebsite
|
Cross-site scripting (XSS) vulnerability in info.php in Bandwebsite (aka Bandsite portal system) 1.5 allows remote attackers to inject arbitrary web script or HTML via the section parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2008-5338
|
2017-09-29 10:32 |
2008-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|