|
292101
|
- |
|
zirkon_box
|
yappa-ng
|
Directory traversal vulnerability in index.php in Fritz Berger yet another php photo album - next generation (yappa-ng) 2.3.2 and possibly other versions through 2.3.3-beta0, when magic_quotes_gpc is…
|
CWE-22
Path Traversal
|
CVE-2008-4626
|
2017-09-29 10:32 |
2008-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292102
|
- |
|
rgallery
|
rgallery_plugin
|
SQL injection vulnerability in the rGallery plugin 1.09 for WoltLab Burning Board (WBB) allows remote attackers to execute arbitrary SQL commands via the itemID parameter in the RGalleryImageWrapper …
|
CWE-89
SQL Injection
|
CVE-2008-4627
|
2017-09-29 10:32 |
2008-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292103
|
- |
|
mywebland
|
minibloggie
|
SQL injection vulnerability in del.php in myWebland miniBloggie 1.0 allows remote attackers to execute arbitrary SQL commands via the post_id parameter.
|
CWE-89
SQL Injection
|
CVE-2008-4628
|
2017-09-29 10:32 |
2008-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292104
|
- |
|
kure
|
kure
|
Multiple directory traversal vulnerabilities in index.php in Kure 0.6.3, when magic_quotes_gpc is disabled, allow remote attackers to read and possibly execute arbitrary local files via a .. (dot dot…
|
CWE-22
Path Traversal
|
CVE-2008-4632
|
2017-09-29 10:32 |
2008-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292105
|
- |
|
astrospaces
|
astrospaces
|
SQL injection vulnerability in profile.php in AstroSPACES 1.1.1 allows remote attackers to execute arbitrary SQL commands via the id parameter in a view action.
|
CWE-89
SQL Injection
|
CVE-2008-4642
|
2017-09-29 10:32 |
2008-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292106
|
- |
|
mywebland
|
mystats
|
SQL injection vulnerability in hits.php in myWebland myStats allows remote attackers to execute arbitrary SQL commands via the sortby parameter.
|
CWE-89
SQL Injection
|
CVE-2008-4643
|
2017-09-29 10:32 |
2008-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292107
|
- |
|
mywebland
|
mystats
|
hits.php in myWebland myStats allows remote attackers to bypass IP address restrictions via a modified X-Forwarded-For HTTP header.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-4644
|
2017-09-29 10:32 |
2008-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292108
|
- |
|
phpwebgallery
|
phpwebgallery
|
plugins/event_tracer/event_list.php in PhpWebGallery 1.7.2 and earlier allows remote authenticated administrators to execute arbitrary PHP code via PHP sequences in the sort parameter, which is proce…
|
CWE-94
Code Injection
|
CVE-2008-4645
|
2017-09-29 10:32 |
2008-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292109
|
- |
|
mywebland
|
myevent
|
SQL injection vulnerability in viewevent.php in myEvent 1.6 allows remote attackers to execute arbitrary SQL commands via the eventdate parameter.
|
CWE-89
SQL Injection
|
CVE-2008-4650
|
2017-09-29 10:32 |
2008-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292110
|
- |
|
dart
|
powertcp_ftp_for_activex
|
Buffer overflow in the ActiveX control (DartFtp.dll) in Dart Communications PowerTCP FTP for ActiveX 2.0.2 0 allows remote attackers to execute arbitrary code via a long SecretKey property.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2008-4652
|
2017-09-29 10:32 |
2008-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|