|
291501
|
- |
|
interface-medien
|
ibase
|
Directory traversal vulnerability in download.php in Interface Medien ibase 2.03 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter.
|
CWE-22
Path Traversal
|
CVE-2008-6288
|
2017-09-29 10:33 |
2009-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291502
|
- |
|
toursmanager
|
tours_manager
|
SQL injection vulnerability in cityview.php in Tours Manager 1.0 allows remote attackers to execute arbitrary SQL commands via the cityid parameter.
|
CWE-89
SQL Injection
|
CVE-2008-6289
|
2017-09-29 10:33 |
2009-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291503
|
- |
|
niclor
|
include_sito
|
Directory traversal vulnerability in includefile.php in nicLOR Sito, when register_globals is enabled or magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary files v…
|
CWE-22
Path Traversal
|
CVE-2008-6290
|
2017-09-29 10:33 |
2009-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291504
|
- |
|
accscripts
|
acc_php_email
|
Acc PHP eMail 1.1 allows remote attackers to bypass authentication and gain administrative access by setting the NEWSLETTERLOGIN cookie to "admin".
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-6291
|
2017-09-29 10:33 |
2009-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291505
|
- |
|
accscripts
|
acc_autos
|
Acc Autos 4.0 allows remote attackers to bypass authentication and gain administrative access by setting the (1) username_cookie to "admin," (2) right_cookie to "1," and (3) id_cookie to "1."
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-6292
|
2017-09-29 10:33 |
2009-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291506
|
- |
|
accscripts
|
acc_real_estate
|
admin/Index.php in Acc Real Estate 4.0 allows remote attackers to bypass authentication and gain administrative access by setting the username_cookie to "admin."
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-6293
|
2017-09-29 10:33 |
2009-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291507
|
- |
|
accscripts
|
acc_statistics
|
admin/Index.php in Acc Statistics 1.1 allows remote attackers to bypass authentication and gain administrative access by setting the username_cookie cookie to "admin."
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-6294
|
2017-09-29 10:33 |
2009-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291508
|
- |
|
maran
|
php_shop
|
admin.php in Maran PHP Shop allows remote attackers to bypass authentication and gain administrative access by setting the user cookie to "demo."
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-6296
|
2017-09-29 10:33 |
2009-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291509
|
- |
|
prezmo
|
small_shoutbox
|
SQL injection vulnerability in shoutbox_view.php in the Small ShoutBox module 1.4 for phpBB allows remote attackers to execute arbitrary SQL commands via the id parameter in a delete action.
|
CWE-89
SQL Injection
|
CVE-2008-6301
|
2017-09-29 10:33 |
2009-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291510
|
- |
|
turnkeyforms
|
local_classifieds
|
TurnkeyForms Local Classifieds allows remote attackers to bypass authentication and gain administrative access via a direct request to Site_Admin/admin.php.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-6302
|
2017-09-29 10:33 |
2009-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|