|
291941
|
- |
|
addalink
|
addalink
|
SQL injection vulnerability in user_read_links.php in Addalink 1.0 beta 4 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the category_id…
|
CWE-89
SQL Injection
|
CVE-2008-4145
|
2017-09-29 10:32 |
2008-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291942
|
- |
|
addalink
|
addalink
|
Addalink 1.0 beta 4 and earlier allows remote attackers to (1) approve web-site additions via a modified approved field and (2) change the visit-counter value via a modified counter field.
|
CWE-287
Improper Authentication
|
CVE-2008-4146
|
2017-09-29 10:32 |
2008-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291943
|
- |
|
dieselscripts
|
diesel_joke_site
|
SQL injection vulnerability in picture_category.php in Diesel Joke Site allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2006-3763.
|
CWE-89
SQL Injection
|
CVE-2008-4150
|
2017-09-29 10:32 |
2008-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291944
|
- |
|
living-e
|
webedition_cms
|
SQL injection vulnerability in living-e webEdition CMS allows remote attackers to execute arbitrary SQL commands via the we_objectID parameter.
|
CWE-89
SQL Injection
|
CVE-2008-4154
|
2017-09-29 10:32 |
2008-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291945
|
- |
|
easybrik
|
easysite
|
Multiple directory traversal vulnerabilities in EasySite 2.3 allow remote attackers to read arbitrary files or list directories via a .. (dot dot) in the (1) module or (2) action parameter in (a) www…
|
CWE-22
Path Traversal
|
CVE-2008-4155
|
2017-09-29 10:32 |
2008-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291946
|
- |
|
customcms
|
gaming_portal
|
SQL injection vulnerability in print.php in CustomCms (CCMS) Gaming Portal 4.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2008-4156
|
2017-09-29 10:32 |
2008-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291947
|
- |
|
vastal
|
phpvid
|
SQL injection vulnerability in groups.php in Vastal I-Tech phpVID 1.1 allows remote attackers to execute arbitrary SQL commands via the cat parameter, a different vector than CVE-2007-3610. NOTE: it…
|
CWE-89
SQL Injection
|
CVE-2008-4157
|
2017-09-29 10:32 |
2008-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291948
|
- |
|
zanfi_solutions
|
zanfi_cms_lite
|
Multiple directory traversal vulnerabilities in index.php in Zanfi CMS lite 1.2 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) flag and (2) inc para…
|
CWE-22
Path Traversal
|
CVE-2008-4158
|
2017-09-29 10:32 |
2008-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291949
|
- |
|
zanfi_solutions
|
jaw_portal zanfi_cms_lite
|
SQL injection vulnerability in index.php in Jaw Portal and Zanfi CMS lite and allows remote attackers to execute arbitrary SQL commands via the page (pageid) parameter.
|
CWE-89
SQL Injection
|
CVE-2008-4159
|
2017-09-29 10:32 |
2008-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291950
|
- |
|
sun
|
opensolaris solaris
|
Unspecified vulnerability in the UFS module in Sun Solaris 8 through 10 and OpenSolaris allows local users to cause a denial of service (NULL pointer dereference and kernel panic) via unknown vectors…
|
CWE-399
Resource Management Errors
|
CVE-2008-4160
|
2017-09-29 10:32 |
2008-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|