|
292691
|
- |
|
turnkeyforms
|
local_classifieds
|
TurnkeyForms Local Classifieds allows remote attackers to bypass authentication and gain administrative access via a direct request to Site_Admin/admin.php.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-6302
|
2017-09-29 10:33 |
2009-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292692
|
- |
|
toursmanager
|
tours_manager
|
SQL injection vulnerability in tourview.php in ToursManager allows remote attackers to execute arbitrary SQL commands via the tourid parameter.
|
CWE-89
SQL Injection
|
CVE-2008-6303
|
2017-09-29 10:33 |
2009-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292693
|
- |
|
freedirectoryscript
|
free_directory_script
|
PHP remote file inclusion vulnerability in init.php in Free Directory Script 1.1.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the API_HOME_D…
|
CWE-94
Code Injection
|
CVE-2008-6305
|
2017-09-29 10:33 |
2009-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292694
|
- |
|
e-topbiz
|
link_back_checker
|
E-topbiz Link Back Checker 1 allows remote attackers to bypass authentication and gain administrative access by setting the auth cookie to "admin."
|
CWE-287
Improper Authentication
|
CVE-2008-6307
|
2017-09-29 10:33 |
2009-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292695
|
- |
|
punbb
|
private_messaging_system
|
Multiple directory traversal vulnerabilities in Private Messaging System (PMS) 1.2.3 and earlier for PunBB allow remote attackers to include and execute arbitrary files via a .. (dot dot) in the pun_…
|
CWE-22
Path Traversal
|
CVE-2008-6308
|
2017-09-29 10:33 |
2009-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292696
|
- |
|
w3matter
|
askpert
|
SQL injection vulnerability in index.php in W3matter AskPert allows remote attackers to execute arbitrary SQL commands via the f[password] parameter. NOTE: some of these details are obtained from th…
|
CWE-89
SQL Injection
|
CVE-2008-6309
|
2017-09-29 10:33 |
2009-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292697
|
- |
|
w3matter
|
revsense
|
SQL injection vulnerability in index.php in W3matter RevSense 1.0 allows remote attackers to execute arbitrary SQL commands via the f[password] parameter. NOTE: some of these details are obtained fr…
|
CWE-89
SQL Injection
|
CVE-2008-6310
|
2017-09-29 10:33 |
2009-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292698
|
- |
|
butterflymedia
|
butterfly_organizer
|
SQL injection vulnerability in view.php in Butterfly Organizer 2.0.1 allows remote attackers to execute arbitrary SQL commands via the mytable parameter. NOTE: the id vector is covered by another CV…
|
CWE-89
SQL Injection
|
CVE-2008-6311
|
2017-09-29 10:33 |
2009-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292699
|
- |
|
manzovi
|
proquiz
|
SQL injection vulnerability in index.php in ProQuiz 1.0 allows remote attackers to execute arbitrary SQL commands via the username parameter.
|
CWE-89
SQL Injection
|
CVE-2008-6312
|
2017-09-29 10:33 |
2009-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292700
|
- |
|
phpaddedit
|
phpaddedit
|
Directory traversal vulnerability in addedit-render.php in phpAddEdit 1.3, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a URL in the edi…
|
CWE-22
Path Traversal
|
CVE-2008-6313
|
2017-09-29 10:33 |
2009-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|