|
292091
|
- |
|
ip_reg
|
ip_reg
|
Multiple SQL injection vulnerabilities in IP Reg 0.4 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) location_id parameter to locationdel.php and (2) vlan_id paramete…
|
CWE-89
SQL Injection
|
CVE-2008-4606
|
2017-09-29 10:32 |
2008-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292092
|
- |
|
portalapp
|
portalapp
|
SQL injection vulnerability in forums.asp in PortalApp 4.0 allows remote attackers to execute arbitrary SQL commands via the sortby parameter.
|
CWE-89
SQL Injection
|
CVE-2008-4613
|
2017-09-29 10:32 |
2008-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292093
|
- |
|
portalapp
|
portalapp
|
PortalApp 4.0 does not require authentication for (1) forums.asp and (2) content.asp, which allows remote attackers to create and delete forums, topics, and replies.
|
CWE-287
Improper Authentication
|
CVE-2008-4614
|
2017-09-29 10:32 |
2008-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292094
|
- |
|
pyxicom
|
actualite
|
SQL injection vulnerability in the actualite module 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2008-4617
|
2017-09-29 10:32 |
2008-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292095
|
- |
|
mrbs
|
mrbs
|
SQL injection vulnerability in Meeting Room Booking System (MRBS) before 1.4 allows remote attackers to execute arbitrary SQL commands via the area parameter to (1) month.php, and possibly (2) day.ph…
|
CWE-89
SQL Injection
|
CVE-2008-4620
|
2017-09-29 10:32 |
2008-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292096
|
- |
|
zeescripts
|
zeeproperty
|
SQL injection vulnerability in bannerclick.php in ZeeScripts Zeeproperty allows remote attackers to execute arbitrary SQL commands via the adid parameter.
|
CWE-89
SQL Injection
|
CVE-2008-4621
|
2017-09-29 10:32 |
2008-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292097
|
- |
|
phpfastnews
|
phpfastnews
|
The isLoggedIn function in fastnews-code.php in phpFastNews 1.0.0 allows remote attackers to bypass authentication and gain administrative access by setting the fn-loggedin cookie to 1.
|
CWE-287
Improper Authentication
|
CVE-2008-4622
|
2017-09-29 10:32 |
2008-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292098
|
- |
|
martin_diphoorn
|
com_ds-syndicate
|
SQL injection vulnerability in the DS-Syndicate (com_ds-syndicate) component 1.1.1 for Joomla allows remote attackers to execute arbitrary SQL commands via the feed_id parameter to index2.php.
|
CWE-89
SQL Injection
|
CVE-2008-4623
|
2017-09-29 10:32 |
2008-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292099
|
- |
|
ftrsoft
|
fast_click_sql_lite
|
PHP remote file inclusion vulnerability in init.php in Fast Click SQL Lite 1.1.7, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the CFG[CDIR] pa…
|
CWE-94
Code Injection
|
CVE-2008-4624
|
2017-09-29 10:32 |
2008-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292100
|
- |
|
shiftthis
|
shifthis_newsletter
|
SQL injection vulnerability in stnl_iframe.php in the ShiftThis Newsletter (st_newsletter) plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the newsletter parameter,…
|
CWE-89
SQL Injection
|
CVE-2008-4625
|
2017-09-29 10:32 |
2008-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|