|
291541
|
- |
|
cms.maury91
|
solarcms
|
SQL injection vulnerability in Forum.php in SolarCMS 0.53.8 and 1.0 allows remote attackers to execute arbitrary SQL commands via the cat parameter to indes.php. NOTE: some of these details are obta…
|
CWE-89
SQL Injection
|
CVE-2008-6345
|
2017-09-29 10:33 |
2009-02-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291542
|
- |
|
luigi_massa
|
onguma_time_sheet
|
PHP remote file inclusion vulnerability in lib/onguma.class.php in the Onguma Time Sheet (com_ongumatimesheet20) 2.0 4b component for Joomla! allows remote attackers to execute arbitrary PHP code via…
|
CWE-94
Code Injection
|
CVE-2008-6347
|
2017-09-29 10:33 |
2009-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291543
|
- |
|
developiteasy
|
photo_gallery
|
Multiple SQL injection vulnerabilities in DevelopItEasy Photo Gallery 1.2 allow remote attackers to execute arbitrary SQL commands via the (1) cat_id parameter to gallery_category.php, (2) photo_id p…
|
CWE-89
SQL Injection
|
CVE-2008-6348
|
2017-09-29 10:33 |
2009-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291544
|
- |
|
turnkeyforms
|
business_survey_pro
|
SQL injection vulnerability in survey_results_text.php in TurnkeyForms Business Survey Pro 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2008-6349
|
2017-09-29 10:33 |
2009-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291545
|
- |
|
turnkeyforms
|
local_classifieds
|
SQL injection vulnerability in listtest.php in TurnkeyForms Local Classifieds allows remote attackers to execute arbitrary SQL commands via the r parameter.
|
CWE-89
SQL Injection
|
CVE-2008-6350
|
2017-09-29 10:33 |
2009-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291546
|
- |
|
turnkeyforms
|
local_classifieds
|
Cross-site scripting (XSS) vulnerability in listtest.php in TurnkeyForms Local Classifieds allows remote attackers to inject arbitrary web script or HTML via the r parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2008-6351
|
2017-09-29 10:33 |
2009-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291547
|
- |
|
xpoze
|
xpoze_pro
|
SQL injection vulnerability in home.html in Xpoze Pro 4.10 allows remote attackers to execute arbitrary SQL commands via the menu parameter.
|
CWE-89
SQL Injection
|
CVE-2008-6352
|
2017-09-29 10:33 |
2009-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291548
|
- |
|
asp-cms
|
asp-cms
|
SQL injection vulnerability in index.asp in ASP-CMS 1.0 allows remote attackers to execute arbitrary SQL commands via the cha parameter.
|
CWE-89
SQL Injection
|
CVE-2008-6353
|
2017-09-29 10:33 |
2009-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291549
|
- |
|
thenetguys
|
aspired2poll
|
The Net Guys ASPired2poll stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing the username and password v…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-6354
|
2017-09-29 10:33 |
2009-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291550
|
- |
|
thenetguys
|
aspired2protect
|
The Net Guys ASPired2Protect stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing the username and passwor…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-6355
|
2017-09-29 10:33 |
2009-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|