|
291901
|
- |
|
yerba
|
yerba
|
Directory traversal vulnerability in index.php in SAC.php (SACphp), as used in Yerba 6.3 and earlier, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the mo…
|
CWE-22
Path Traversal
|
CVE-2008-4486
|
2017-09-29 10:32 |
2008-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291902
|
- |
|
phpabook
|
phpabook
|
Directory traversal vulnerability in config.inc.php in phpAbook 0.8.8b and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (d…
|
CWE-22
Path Traversal
|
CVE-2008-4490
|
2017-09-29 10:32 |
2008-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291903
|
- |
|
yourownbux
|
yourownbux
|
SQL injection vulnerability in referrals.php in YourOwnBux 4.0 allows remote attackers to execute arbitrary SQL commands via the usNick cookie.
|
CWE-89
SQL Injection
|
CVE-2008-4492
|
2017-09-29 10:32 |
2008-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291904
|
- |
|
microsoft
|
digital_image
|
Microsoft PicturePusher ActiveX control (PipPPush.DLL 7.00.0709), as used in Microsoft Digital Image 2006 Starter Edition, allows remote attackers to force the upload of arbitrary files by using the …
|
NVD-CWE-noinfo CWE-20
Improper Input Validation
|
CVE-2008-4493
|
2017-09-29 10:32 |
2008-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291905
|
- |
|
torrenttrader
|
torrenttrader
|
SQL injection vulnerability in completed-advance.php in TorrentTrader Classic 1.08 and 1.04 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2008-4494
|
2017-09-29 10:32 |
2008-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291906
|
- |
|
select_development_solutions
|
php_auto_dealer
|
SQL injection vulnerability in view_cat.php in PHP Auto Dealer 2.7 allows remote attackers to execute arbitrary SQL commands via the v_cat parameter.
|
CWE-89
SQL Injection
|
CVE-2008-4495
|
2017-09-29 10:32 |
2008-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291907
|
- |
|
select_development_solutions
|
php_realtor
|
SQL injection vulnerability in view_cat.php in PHP Realtor 1.5 allows remote attackers to execute arbitrary SQL commands via the v_cat parameter.
|
CWE-89
SQL Injection
|
CVE-2008-4496
|
2017-09-29 10:32 |
2008-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291908
|
- |
|
built2go
|
real_estate_listings
|
SQL injection vulnerability in event_detail.php in Built2Go Real Estate Listings 1.5 allows remote attackers to execute arbitrary SQL commands via the event_id parameter.
|
CWE-89
SQL Injection
|
CVE-2008-4497
|
2017-09-29 10:32 |
2008-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291909
|
- |
|
phpautos
|
phpautos
|
SQL injection vulnerability in searchresults.php in PHP Autos 2.9.1 allows remote attackers to execute arbitrary SQL commands via the catid parameter.
|
CWE-89
SQL Injection
|
CVE-2008-4498
|
2017-09-29 10:32 |
2008-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291910
|
- |
|
datafeedfile
|
dff_framework_api
|
Multiple PHP remote file inclusion vulnerabilities in DataFeedFile (DFF) PHP Framework API allow remote attackers to execute arbitrary PHP code via a URL in the DFF_config[dir_include] parameter to (…
|
CWE-94
Code Injection
|
CVE-2008-4502
|
2017-09-29 10:32 |
2008-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|