|
291981
|
- |
|
openengine
|
openengine
|
PHP remote file inclusion vulnerability in cms/system/openengine.php in openEngine 2.0 beta4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the oe_classpath parameter.
|
CWE-20
Improper Input Validation
|
CVE-2008-4329
|
2017-09-29 10:32 |
2008-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291982
|
- |
|
lansuite
|
lansuite
|
Directory traversal vulnerability in index.php in LanSuite 3.3.2 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the design parameter.
|
CWE-22
Path Traversal
|
CVE-2008-4330
|
2017-09-29 10:32 |
2008-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291983
|
- |
|
phpocs
|
phpocs
|
Directory traversal vulnerability in library/pagefunctions.inc.php in phpOCS 0.1 beta3 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the act p…
|
CWE-22
Path Traversal
|
CVE-2008-4331
|
2017-09-29 10:32 |
2008-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291984
|
- |
|
cannot
|
php_infoboard
|
SQL injection vulnerability in the showjavatopic function in func.php in PHP infoBoard V.7 Plus allows remote attackers to execute arbitrary SQL commands via the idcat parameter to showtopic.php.
|
CWE-89
SQL Injection
|
CVE-2008-4332
|
2017-09-29 10:32 |
2008-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291985
|
- |
|
cannot
|
php_infoboard
|
Cross-site scripting (XSS) vulnerability in PHP infoBoard V.7 Plus allows remote attackers to inject arbitrary web script or HTML via the isname parameter in a newtopic action.
|
CWE-79
Cross-site Scripting
|
CVE-2008-4333
|
2017-09-29 10:32 |
2008-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291986
|
- |
|
cannot
|
php_infoboard
|
PHP infoBoard V.7 Plus allows remote attackers to bypass authentication and gain administrative access by setting the infouser cookie to 1.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-4334
|
2017-09-29 10:32 |
2008-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291987
|
- |
|
atomic_photo_album
|
atomic_photo_album
|
SQL injection vulnerability in album.php in Atomic Photo Album (APA) 1.1.0pre4 allows remote attackers to execute arbitrary SQL commands via the apa_album_ID parameter.
|
CWE-89
SQL Injection
|
CVE-2008-4335
|
2017-09-29 10:32 |
2008-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291988
|
- |
|
constantin_charissis
|
atomic_photo_album
|
Cross-site scripting (XSS) vulnerability in album.php in Atomic Photo Album (APA) 1.1.0pre4 allows remote attackers to inject arbitrary web script or HTML via the apa_album_ID parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2008-4336
|
2017-09-29 10:32 |
2008-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291989
|
- |
|
myblog
|
myblog
|
add.php in MyBlog 0.9.8 and earlier allows remote attackers to bypass authentication and gain administrative access by setting a cookie with admin=yes and login=admin.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-4341
|
2017-09-29 10:32 |
2008-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291990
|
- |
|
webportal
|
webportal_cms
|
SQL injection vulnerability in download.php in WebPortal CMS 0.7.4 and earlier allows remote attackers to execute arbitrary SQL commands via the aid parameter.
|
CWE-89
SQL Injection
|
CVE-2008-4345
|
2017-09-29 10:32 |
2008-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|