|
293331
|
- |
|
eazyportal
|
eazyportal
|
SQL injection vulnerability in index.php in eazyPortal 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the session_vars cookie.
|
CWE-89
SQL Injection
|
CVE-2008-1121
|
2017-09-29 10:30 |
2008-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293332
|
- |
|
sitebuilder
|
sitebuilder_elite
|
Multiple PHP remote file inclusion vulnerabilities in SiteBuilder Elite 1.2 allow remote attackers to execute arbitrary PHP code via a URL in the CarpPath parameter to (1) files/carprss.php and (2) f…
|
CWE-94
Code Injection
|
CVE-2008-1123
|
2017-09-29 10:30 |
2008-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293333
|
- |
|
podcast_generator
|
podcast_generator
|
Multiple PHP remote file inclusion vulnerabilities in Podcast Generator 1.0 BETA 2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the absoluteurl parameter to (1) compo…
|
CWE-94
Code Injection
|
CVE-2008-1124
|
2017-09-29 10:30 |
2008-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293334
|
- |
|
podcast_generator
|
podcast_generator
|
Multiple directory traversal vulnerabilities in Podcast Generator 1.0 BETA 2 and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) theme_path parameter to core/them…
|
CWE-22
Path Traversal
|
CVE-2008-1125
|
2017-09-29 10:30 |
2008-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293335
|
- |
|
barryvan_compo
|
barryvan_compo_manager
|
PHP remote file inclusion vulnerability in main.php in Barryvan Compo Manager 0.3 allows remote attackers to execute arbitrary PHP code via a URL in the pageURL parameter.
|
CWE-94
Code Injection
|
CVE-2008-1126
|
2017-09-29 10:30 |
2008-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293336
|
- |
|
barryvan_compo
|
barryvan_compo_manager
|
More information available at:
http://www.securityfocus.com/bid/28035/info
|
CWE-94
Code Injection
|
CVE-2008-1126
|
2017-09-29 10:30 |
2008-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293337
|
- |
|
crytek
|
crysis
|
Format string vulnerability in the cryactio function in Crysis 1.1.1.5879 allows remote authenticated users to execute arbitrary code via format string specifiers in the user name, which is triggered…
|
CWE-134
Use of Externally-Controlled Format String
|
CVE-2008-1127
|
2017-09-29 10:30 |
2008-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293338
|
- |
|
deslock
|
deslock
|
DLMFENC.sys 1.0.0.26 in DESlock+ 3.2.6 and earlier allows local users to cause a denial of service (system crash) via a certain ZERO_MEM DLMFENC_IOCTL request to \\.\DLKPFSD_Device, aka the "ring0 li…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2008-1138
|
2017-09-29 10:30 |
2008-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293339
|
- |
|
deslock
|
deslock
|
DESlock+ 3.2.6 and earlier, when DLMFENC.sys 1.0.0.26 and DLMFDISK.sys 1.2.0.27 are present, allows local users to gain privileges via a certain DLMFENC_IOCTL request to \\.\DLKPFSD_Device that overw…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-1139
|
2017-09-29 10:30 |
2008-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293340
|
- |
|
deslock
|
deslock
|
DLMFDISK.sys 1.2.0.27 in DESlock+ 3.2.6 and earlier allows local users to gain privileges via a certain DLKFDISK_IOCTL request to \\.\DLKFDisk_Control that overwrites a data structure associated with…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-1140
|
2017-09-29 10:30 |
2008-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|