|
291961
|
- |
|
integramod
|
integramod
|
IntegraMOD 1.4.x stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a backup via a direct request to a backup/backup-yyyy-dd-m…
|
CWE-200
Information Exposure
|
CVE-2008-4183
|
2017-09-29 10:32 |
2008-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291962
|
- |
|
webcms
|
webcms_portal_edition
|
SQL injection vulnerability in index.php in webCMS Portal Edition allows remote attackers to execute arbitrary SQL commands via the id parameter in a documentos action, a different vector than CVE-20…
|
CWE-89
SQL Injection
|
CVE-2008-4185
|
2017-09-29 10:32 |
2008-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291963
|
- |
|
proactive_cms
|
proactive_cms
|
Directory traversal vulnerability in index.php in ProActive CMS allows remote attackers to read arbitrary files via a .. (dot dot) in the template parameter.
|
CWE-22
Path Traversal
|
CVE-2008-4187
|
2017-09-29 10:32 |
2008-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291964
|
- |
|
alt-n
|
securitygateway
|
Stack-based buffer overflow in SecurityGateway.dll in Alt-N Technologies SecurityGateway 1.0.1 allows remote attackers to execute arbitrary code via a long username parameter.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2008-4193
|
2017-09-29 10:32 |
2008-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291965
|
- |
|
gonafish
|
linkscaffepro
|
SQL injection vulnerability in index.php in Gonafish LinksCaffePRO 4.5 allows remote attackers to execute arbitrary SQL commands via the idd parameter in a deadlink action.
|
CWE-89
SQL Injection
|
CVE-2008-4202
|
2017-09-29 10:32 |
2008-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291966
|
- |
|
czaries
|
czarnews
|
SQL injection vulnerability in cn_users.php in CzarNews 1.20 and earlier allows remote attackers to execute arbitrary SQL commands via a recook cookie.
|
CWE-89
SQL Injection
|
CVE-2008-4203
|
2017-09-29 10:32 |
2008-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291967
|
- |
|
softacid
|
hotel_reservation_system
|
SQL injection vulnerability in city.asp in SoftAcid Hotel Reservation System (HRS) allows remote attackers to execute arbitrary SQL commands via the city parameter.
|
CWE-89
SQL Injection
|
CVE-2008-4204
|
2017-09-29 10:32 |
2008-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291968
|
- |
|
xmlsoft
|
libxml
|
Integer overflow in the xmlBufferResize function in libxml2 2.7.2 allows context-dependent attackers to cause a denial of service (infinite loop) via a large XML document.
|
CWE-189
Numeric Errors
|
CVE-2008-4225
|
2017-09-29 10:32 |
2008-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291969
|
- |
|
xmlsoft
|
libxml
|
Integer overflow in the xmlSAX2Characters function in libxml2 2.7.2 allows context-dependent attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a large …
|
CWE-399
Resource Management Errors
|
CVE-2008-4226
|
2017-09-29 10:32 |
2008-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291970
|
- |
|
cj
|
ultra_plus
|
SQL injection vulnerability in CJ Ultra Plus 1.0.4 and earlier allows remote attackers to execute arbitrary SQL commands via an SID cookie.
|
CWE-89
SQL Injection
|
CVE-2008-4241
|
2017-09-29 10:32 |
2008-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|