|
291571
|
- |
|
aspportal
|
aspportal
|
ASP Portal 3.2.5 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request to ASPPortal.mdb.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-6382
|
2017-09-29 10:33 |
2009-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291572
|
- |
|
activewebsoftwares
|
quick_tree_view_.net
|
Quick Tree View .NET 3.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request to qtv.mdb.
|
CWE-200
Information Exposure
|
CVE-2008-6387
|
2017-09-29 10:33 |
2009-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291573
|
- |
|
4u2ges
|
rapid_classified
|
Rapid Classified 3.1 and 3.15 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request to cld…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-6388
|
2017-09-29 10:33 |
2009-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291574
|
- |
|
aliensoftcorp
|
rae_media_contact_management
|
SQL injection vulnerability in asadmin/default.asp in Rae Media Contact Management Software SOHO, Standard, and Enterprise allows remote attackers to execute arbitrary SQL commands via the Password p…
|
CWE-89
SQL Injection
|
CVE-2008-6389
|
2017-09-29 10:33 |
2009-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291575
|
- |
|
ocean12tech
|
membership_manager_pro
|
SQL injection vulnerability in login.asp in Ocean12 Membership Manager Pro allows remote attackers to execute arbitrary SQL commands via the Password parameter. NOTE: the provenance of this informat…
|
CWE-89
SQL Injection
|
CVE-2008-6390
|
2017-09-29 10:33 |
2009-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291576
|
- |
|
psi-im
|
psi
|
PSI Jabber client before 0.12.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a file transfer request with a negative value in a SOCKS5 option, …
|
CWE-189
Numeric Errors
|
CVE-2008-6393
|
2017-09-29 10:33 |
2009-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291577
|
- |
|
jetik
|
jetik-web
|
SQL injection vulnerability in sayfa.php in JETIK-WEB allows remote attackers to execute arbitrary SQL commands via the kat parameter.
|
CWE-89
SQL Injection
|
CVE-2008-6401
|
2017-09-29 10:33 |
2009-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291578
|
- |
|
muskatli
|
sofi_webgui
|
PHP remote file inclusion vulnerability in hu/modules/reg-new/modstart.php in Sofi WebGui 0.6.3 PRE and earlier allows remote attackers to execute arbitrary PHP code via a URL in the mod_dir paramete…
|
CWE-94
Code Injection
|
CVE-2008-6402
|
2017-09-29 10:33 |
2009-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291579
|
- |
|
openrat
|
openrat
|
PHP remote file inclusion vulnerability in themes/default/include/html/insert.inc.php in OpenRat 0.8-beta4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the tpl_dir p…
|
CWE-94
Code Injection
|
CVE-2008-6403
|
2017-09-29 10:33 |
2009-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291580
|
- |
|
greatclone
|
hotscripts_clone
|
SQL injection vulnerability in showcategory.php in Hotscripts Clone allows remote attackers to execute arbitrary SQL commands via the cid parameter.
|
CWE-89
SQL Injection
|
CVE-2008-6405
|
2017-09-29 10:33 |
2009-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|