|
291951
|
- |
|
assetman
|
assetman
|
SQL injection vulnerability in search_inv.php in Assetman 2.5b allows remote attackers to execute arbitrary SQL commands and conduct session fixation attacks via a combination of crafted order and or…
|
CWE-89
SQL Injection
|
CVE-2008-4161
|
2017-09-29 10:32 |
2008-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291952
|
- |
|
memht
|
memht_portal
|
cron.php in MemHT Portal 3.9.0 and earlier allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message.
|
CWE-200
Information Exposure
|
CVE-2008-4164
|
2017-09-29 10:32 |
2008-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291953
|
- |
|
ezphotogallery
|
ezphotogallery
|
useradmin.php in Easy Photo Gallery (aka Ezphotogallery) 2.1 does not require administrative authentication, which allows remote attackers to (1) add or (2) remove an Administrator account.
|
CWE-287
Improper Authentication
|
CVE-2008-4167
|
2017-09-29 10:32 |
2008-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291954
|
- |
|
iscripts
|
easyindex
|
SQL injection vulnerability in detaillist.php in iScripts EasyIndex, possibly 1.0, allows remote attackers to execute arbitrary SQL commands via the produid parameter.
|
CWE-89
SQL Injection
|
CVE-2008-4169
|
2017-09-29 10:32 |
2008-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291955
|
- |
|
proarcadescript
|
proarcadescript
|
SQL injection vulnerability in ProArcadeScript 1.3 allows remote attackers to execute arbitrary SQL commands via the random parameter to the default URI.
|
CWE-89
SQL Injection
|
CVE-2008-4173
|
2017-09-29 10:32 |
2008-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291956
|
- |
|
linkbidscript
|
linkbidscript
|
Multiple SQL injection vulnerabilities in Link Bid Script 1.5 allow remote attackers to execute arbitrary SQL commands via the (1) ucat parameter to upgrade.php and the (2) id parameter to linkadmin/…
|
CWE-89
SQL Injection
|
CVE-2008-4175
|
2017-09-29 10:32 |
2008-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291957
|
- |
|
asp_indir
|
fot_video_scripti
|
SQL injection vulnerability in izle.asp in FoT Video scripti 1.1 beta allows remote attackers to execute arbitrary SQL commands via the oyun parameter.
|
CWE-89
SQL Injection
|
CVE-2008-4176
|
2017-09-29 10:32 |
2008-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291958
|
- |
|
preprojects
|
pre_real_estate_listings
|
SQL injection vulnerability in search.php in Pre Real Estate Listings allows remote attackers to execute arbitrary SQL commands via the c parameter.
|
CWE-89
SQL Injection
|
CVE-2008-4177
|
2017-09-29 10:32 |
2008-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291959
|
- |
|
downline_goldmine
|
builder new_addon
|
SQL injection vulnerability in tr.php in DownlineGoldmine Special Category Addon, Downline Builder Pro, New Addon, and Downline Goldmine Builder allows remote attackers to execute arbitrary SQL comma…
|
CWE-89
SQL Injection
|
CVE-2008-4178
|
2017-09-29 10:32 |
2008-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291960
|
- |
|
netenberg
|
fantastico_de_luxe
|
Directory traversal vulnerability in includes/xml.php in the Netenberg Fantastico De Luxe module before 2.10.4 r19 for cPanel, when cPanel PHP Register Globals is enabled, allows remote authenticated…
|
CWE-22
Path Traversal
|
CVE-2008-4181
|
2017-09-29 10:32 |
2008-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|