|
291561
|
- |
|
ocean12tech
|
contact_manager_pro
|
SQL injection vulnerability in default.asp in Ocean12 Contact Manager Pro 1.02 allows remote attackers to execute arbitrary SQL commands via the Sort parameter.
|
CWE-89
SQL Injection
|
CVE-2008-6369
|
2017-09-29 10:33 |
2009-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291562
|
- |
|
ocean12tech
|
contact_manager_pro
|
Cross-site scripting (XSS) vulnerability in default.asp in Ocean12 Contact Manager Pro 1.02 allows remote attackers to inject arbitrary web script or HTML via the DisplayFormat parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2008-6370
|
2017-09-29 10:33 |
2009-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291563
|
- |
|
ocean12tech
|
membership_manager_pro
|
SQL injection vulnerability in login.asp in Ocean12 Membership Manager Pro allows remote attackers to execute arbitrary SQL commands via the username (Username parameter).
|
CWE-89
SQL Injection
|
CVE-2008-6371
|
2017-09-29 10:33 |
2009-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291564
|
- |
|
ocean12tech
|
faq_manager_pro
|
SQL injection vulnerability in default.asp in Ocean12 FAQ Manager Pro 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter in a Cat action. NOTE: some of these details …
|
CWE-89
SQL Injection
|
CVE-2008-6372
|
2017-09-29 10:33 |
2009-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291565
|
- |
|
codefixer
|
mailinglistpro
|
CodefixerSoftware MailingListPro Free Edition stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a dir…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-6374
|
2017-09-29 10:33 |
2009-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291566
|
- |
|
phpbb-seo
|
multi_seo_phpbb
|
PHP remote file inclusion vulnerability in include/global.php in Multi SEO phpBB 1.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the pfad parameter.
|
CWE-94
Code Injection
|
CVE-2008-6377
|
2017-09-29 10:33 |
2009-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291567
|
- |
|
mxmania
|
calendar_mx_professional
|
SQL injection vulnerability in calendar_Eventupdate.asp in Calendar Mx Professional 2.0.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.
|
CWE-89
SQL Injection
|
CVE-2008-6378
|
2017-09-29 10:33 |
2009-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291568
|
- |
|
mxmania
|
gallery_mx
|
SQL injection vulnerability in pics_pre.asp in Gallery MX 2.0.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.
|
CWE-89
SQL Injection
|
CVE-2008-6379
|
2017-09-29 10:33 |
2009-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291569
|
- |
|
activewebsoftwares
|
active_web_helpdesk
|
SQL injection vulnerability in default.aspx in Active Web Helpdesk 2.0 allows remote attackers to execute arbitrary SQL commands via the CategoryID parameter.
|
CWE-89
SQL Injection
|
CVE-2008-6380
|
2017-09-29 10:33 |
2009-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291570
|
- |
|
bcoos
|
bcoos
|
SQL injection vulnerability in modules/adresses/viewcat.php in bcoos 1.0.13, and possibly earlier, allows remote authenticated users with Addresses module permissions to execute arbitrary SQL command…
|
CWE-89
SQL Injection
|
CVE-2008-6381
|
2017-09-29 10:33 |
2009-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|