|
292001
|
- |
|
powie
|
plink
|
SQL injection vulnerability in linkto.php in Powie pLink 2.07 allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2008-4357
|
2017-09-29 10:32 |
2008-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292002
|
- |
|
powerportal
|
powerportal
|
Directory traversal vulnerability in PowerPortal 2.0.13 allows remote attackers to list and possibly read arbitrary files via a .. (dot dot) in the path parameter to the default URI.
|
CWE-22
Path Traversal
|
CVE-2008-4361
|
2017-09-29 10:32 |
2008-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292003
|
- |
|
deslock
|
deslock
|
The Virtual Token driver (vdlptokn.sys) 1.0.2.43 in DESlock+ 3.2.7 allows local users to cause a denial of service (system crash) via a crafted IOCTL request to \Device\DLPTokenWalter0.
|
CWE-399
Resource Management Errors
|
CVE-2008-4362
|
2017-09-29 10:32 |
2008-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292004
|
- |
|
deslock
|
deslock
|
DLMFENC.sys 1.0.0.28 in DESlock+ 3.2.7 allows local users to cause a denial of service (system crash) or potentially execute arbitrary code via a certain DLMFENC_IOCTL request to \\.\DLKPFSD_Device t…
|
CWE-20
Improper Input Validation
|
CVE-2008-4363
|
2017-09-29 10:32 |
2008-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292005
|
- |
|
camera_life
|
camera_life
|
Unrestricted file upload vulnerability in the image upload component in Camera Life 2.6.2b4 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extensio…
|
CWE-20
Improper Input Validation
|
CVE-2008-4366
|
2017-09-29 10:32 |
2008-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292006
|
- |
|
availscript
|
availscript_photo_album
|
SQL injection vulnerability in pics.php in Availscript Photo Album allows remote attackers to execute arbitrary SQL commands via the sid parameter.
|
CWE-89
SQL Injection
|
CVE-2008-4369
|
2017-09-29 10:32 |
2008-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292007
|
- |
|
availscript
|
availscript_photo_album
|
Multiple cross-site scripting (XSS) vulnerabilities in Availscript Photo Album allow remote attackers to inject arbitrary web script or HTML via the (1) sid parameter to pics.php and the (2) a parame…
|
CWE-79
Cross-site Scripting
|
CVE-2008-4370
|
2017-09-29 10:32 |
2008-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292008
|
- |
|
availscript
|
availscript_article_script
|
SQL injection vulnerability in articles.php in AvailScript Article Script allows remote attackers to execute arbitrary SQL commands via the aIDS parameter.
|
CWE-89
SQL Injection
|
CVE-2008-4371
|
2017-09-29 10:32 |
2008-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292009
|
- |
|
availscript
|
availscript_article_script
|
Cross-site scripting (XSS) vulnerability in articles.php in AvailScript Article Script allows remote attackers to inject arbitrary web script or HTML via the aIDS parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2008-4372
|
2017-09-29 10:32 |
2008-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292010
|
- |
|
availscript
|
availscript_jobs_portal_script
|
SQL injection vulnerability in job_seeker/applynow.php in AvailScript Job Portal Script allows remote attackers to execute arbitrary SQL commands via the jid parameter.
|
CWE-89
SQL Injection
|
CVE-2008-4373
|
2017-09-29 10:32 |
2008-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|