|
292351
|
- |
|
bonzacart
|
bonza_cart
|
Cross-site request forgery (CSRF) vulnerability in admin/ad_settings.php in Bonza Cart 1.10 and earlier allows remote attackers to change the admin password via a logout action in conjunction with th…
|
CWE-352
Origin Validation Error
|
CVE-2008-5567
|
2017-09-29 10:32 |
2008-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292352
|
- |
|
ipn-mate
|
ipn_pro_3
|
Cross-site request forgery (CSRF) vulnerability in admin/settings.php in IPN Pro 3 1.44 and earlier allows remote attackers to change the admin password via a logout action in conjunction with the ad…
|
CWE-352
Origin Validation Error
|
CVE-2008-5568
|
2017-09-29 10:32 |
2008-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292353
|
- |
|
php_multiple_newsletters
|
php_multiple_newsletters
|
Directory traversal vulnerability in index.php in PHP Multiple Newsletters 2.7, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot d…
|
CWE-22
Path Traversal
|
CVE-2008-5570
|
2017-09-29 10:32 |
2008-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292354
|
- |
|
dotnetindex
|
professional_download_assistant
|
SQL injection vulnerability in admin/login.asp in Professional Download Assistant 0.1 allows remote attackers to execute arbitrary SQL commands via the (1) uname parameter (aka user field) or the (2)…
|
CWE-89
SQL Injection
|
CVE-2008-5571
|
2017-09-29 10:32 |
2008-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292355
|
- |
|
dotnetindex
|
professional_download_assistant
|
Professional Download Assistant 0.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-5572
|
2017-09-29 10:32 |
2008-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292356
|
- |
|
adcomplete
|
poll_pro
|
SQL injection vulnerability in the login feature in Poll Pro 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) Password and (2) username parameters.
|
CWE-89
SQL Injection
|
CVE-2008-5573
|
2017-09-29 10:32 |
2008-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292357
|
- |
|
unscripts
|
webmaster_marketplace
|
SQL injection vulnerability in member.php in Webmaster Marketplace allows remote attackers to execute arbitrary SQL commands via the u parameter.
|
CWE-89
SQL Injection
|
CVE-2008-5574
|
2017-09-29 10:32 |
2008-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292358
|
- |
|
scssboard
|
scssboard
|
admin/forums.php in sCssBoard 1.0, 1.1, 1.11, and 1.12 allows remote attackers to bypass authentication and gain administrative access via a large value of the current_user[users_level] parameter.
|
CWE-287
Improper Authentication
|
CVE-2008-5576
|
2017-09-29 10:32 |
2008-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292359
|
- |
|
scssboard
|
scssboard
|
PHP remote file inclusion vulnerability in index.php in sCssBoard 1.0, 1.1, 1.11, and 1.12 allows remote attackers to execute arbitrary PHP code via a URL in the inc_function parameter.
|
CWE-94
Code Injection
|
CVE-2008-5577
|
2017-09-29 10:32 |
2008-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292360
|
- |
|
scssboard
|
scssboard
|
Multiple SQL injection vulnerabilities in index.php in sCssBoard 1.0, 1.1, 1.11, and 1.12 allow remote attackers to execute arbitrary SQL commands via (1) the f parameter in a showforum action, (2) t…
|
CWE-89
SQL Injection
|
CVE-2008-5578
|
2017-09-29 10:32 |
2008-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|