|
291941
|
- |
|
phpwebgallery
|
phpwebgallery
|
Multiple cross-site scripting (XSS) vulnerabilities in admin/include/isadmin.inc.php in PhpWebGallery 1.3.4 allow remote attackers to inject arbitrary web script or HTML via the (1) lang[access_forbi…
|
CWE-79
Cross-site Scripting
|
CVE-2008-4591
|
2017-09-29 10:32 |
2008-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291942
|
- |
|
sportspanel
|
sports_clubs_web_portal
|
Directory traversal vulnerability in index.php in Sports Clubs Web Panel 0.0.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the p parameter.
|
NVD-CWE-noinfo CWE-22
Path Traversal
|
CVE-2008-4592
|
2017-09-29 10:32 |
2008-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291943
|
- |
|
mosaic_commerce
|
mosaic_commerce
|
SQL injection vulnerability in category.php in Mosaic Commerce allows remote attackers to execute arbitrary SQL commands via the cid parameter.
|
CWE-89
SQL Injection
|
CVE-2008-4599
|
2017-09-29 10:32 |
2008-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291944
|
- |
|
steve_dawson
|
pokermax_poker_league_tournament_script
|
configure.php in PokerMax Poker League Tournament Script 0.13 allows remote attackers to bypass authentication and gain administrative access by setting the ValidUserAdmin cookie.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-4600
|
2017-09-29 10:32 |
2008-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291945
|
- |
|
qualityunit
|
post_affiliate_pro
|
Directory traversal vulnerability in index.php in Post Affiliate Pro 2.0 allows remote authenticated users to read and possibly execute arbitrary local files via a .. (dot dot) in the md parameter.
|
CWE-22
Path Traversal
|
CVE-2008-4602
|
2017-09-29 10:32 |
2008-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291946
|
- |
|
igaming
|
cms
|
SQL injection vulnerability in search.php in iGaming CMS 2.0 Alpha 1 allows remote attackers to execute arbitrary SQL commands via the keywords parameter in a search_games action.
|
CWE-89
SQL Injection
|
CVE-2008-4603
|
2017-09-29 10:32 |
2008-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291947
|
- |
|
cafeengine
|
easycafeengine
|
SQL injection vulnerability in index.php in Easy CafeEngine 1.1 allows remote attackers to execute arbitrary SQL commands via the itemid parameter.
|
CWE-89
SQL Injection
|
CVE-2008-4604
|
2017-09-29 10:32 |
2008-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291948
|
- |
|
cafeengine
|
easycafeengine
|
SQL injection vulnerability in CafeEngine allows remote attackers to execute arbitrary SQL commands via the id parameter to (1) dish.php and (2) menu.php.
|
CWE-89
SQL Injection
|
CVE-2008-4605
|
2017-09-29 10:32 |
2008-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291949
|
- |
|
ip_reg
|
ip_reg
|
Multiple SQL injection vulnerabilities in IP Reg 0.4 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) location_id parameter to locationdel.php and (2) vlan_id paramete…
|
CWE-89
SQL Injection
|
CVE-2008-4606
|
2017-09-29 10:32 |
2008-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291950
|
- |
|
portalapp
|
portalapp
|
SQL injection vulnerability in forums.asp in PortalApp 4.0 allows remote attackers to execute arbitrary SQL commands via the sortby parameter.
|
CWE-89
SQL Injection
|
CVE-2008-4613
|
2017-09-29 10:32 |
2008-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|