|
292941
|
- |
|
mywebland
|
mybloggie
|
Cross-site request forgery (CSRF) vulnerability in admin.php in myWebland myBloggie 2.1.6 allows remote attackers to perform edit actions as administrators. NOTE: this can be leveraged to execute SQ…
|
CWE-352
Origin Validation Error
|
CVE-2008-3080
|
2017-09-29 10:31 |
2008-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292942
|
- |
|
brightcode joomla
|
brightcode_weblinks_module com_brightweblinks
|
SQL injection vulnerability in Brightcode Weblinks (com_brightweblinks) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter.
|
CWE-89
SQL Injection
|
CVE-2008-3083
|
2017-09-29 10:31 |
2008-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292943
|
- |
|
kasseler-cms
|
kasseler_cms
|
Directory traversal vulnerability in Kasseler CMS 1.3.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter to index.php, possibly related to the phpManual module.
|
CWE-22
Path Traversal
|
CVE-2008-3087
|
2017-09-29 10:31 |
2008-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292944
|
- |
|
kasseler-cms
|
kasseler_cms
|
Cross-site scripting (XSS) vulnerability in the Files module in Kasseler CMS 1.3.0 and 1.3.1 Lite allows remote attackers to inject arbitrary web script or HTML via the cid parameter in a Category ac…
|
CWE-79
Cross-site Scripting
|
CVE-2008-3088
|
2017-09-29 10:31 |
2008-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292945
|
- |
|
xpoze
|
xpoze_pro
|
SQL injection vulnerability in user.html in Xpoze Pro 3.06 (aka Xpoze Pro CMS 2008) allows remote attackers to execute arbitrary SQL commands via the uid parameter.
|
CWE-89
SQL Injection
|
CVE-2008-3089
|
2017-09-29 10:31 |
2008-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292946
|
- |
|
phplizardo
|
imperialbb
|
Unrestricted file upload vulnerability in ImperialBB 2.3.5 and earlier allows remote authenticated users to upload and execute arbitrary PHP code by placing a .php filename in the Upload_Avatar param…
|
CWE-94
Code Injection
|
CVE-2008-3093
|
2017-09-29 10:31 |
2008-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292947
|
- |
|
phpmotion
|
phpmotion
|
Unrestricted file upload vulnerability in update_profile.php in PHPmotion 2.0 and earlier allows remote authenticated users to execute arbitrary code by uploading a .php file with a content type of (…
|
CWE-20
Improper Input Validation
|
CVE-2008-3117
|
2017-09-29 10:31 |
2008-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292948
|
- |
|
phpmotion
|
phpmotion
|
Information from the vendor and further analysis show that the application is not affected by these issues.
|
CWE-20
Improper Input Validation
|
CVE-2008-3117
|
2017-09-29 10:31 |
2008-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292949
|
- |
|
phpmotion
|
phpmotion
|
SQL injection vulnerability in play.php in PHPmotion 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the vid parameter.
|
CWE-89
SQL Injection
|
CVE-2008-3118
|
2017-09-29 10:31 |
2008-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292950
|
- |
|
phpmotion
|
phpmotion
|
RETIRED: Information from the vendor and further analysis show that the application is not affected by these issues.
|
CWE-89
SQL Injection
|
CVE-2008-3118
|
2017-09-29 10:31 |
2008-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|