|
292191
|
- |
|
w1n78
|
lyrics
|
SQL injection vulnerability in lyrics_song.php in the Lyrics (lyrics_menu) plugin 0.42 for e107 allows remote attackers to execute arbitrary SQL commands via the l_id parameter. NOTE: some of these …
|
CWE-89
SQL Injection
|
CVE-2008-4906
|
2017-09-29 10:32 |
2008-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292192
|
- |
|
rs_maxsoft
|
fotogalerie
|
SQL injection vulnerability in popup_img.php in the fotogalerie module in RS MAXSOFT allows remote attackers to execute arbitrary SQL commands via the fotoID parameter. NOTE: this issue was disclose…
|
CWE-89
SQL Injection
|
CVE-2008-4912
|
2017-09-29 10:32 |
2008-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292193
|
- |
|
lokicms
|
lokicms
|
Directory traversal vulnerability in admin.php in LokiCMS 0.3.3 and earlier allows remote attackers to delete arbitrary files via a .. (dot dot) in the delete parameter.
|
CWE-22
Path Traversal
|
CVE-2008-4913
|
2017-09-29 10:32 |
2008-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292194
|
- |
|
vmware
|
esx esxi
|
Unspecified vulnerability in VMware ESXi 3.5 before ESXe350-200901401-I-SG and ESX 3.5 before ESX350-200901401-SG allows local administrators to cause a denial of service (host crash) via a snapshot …
|
NVD-CWE-noinfo
|
CVE-2008-4914
|
2017-09-29 10:32 |
2009-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292195
|
- |
|
emc vmware
|
vmware_player vmware_ace vmware_esx vmware_esxi vmware_server vmware_workstation
|
Unspecified vulnerability in a guest virtual device driver in VMware Workstation before 5.5.9 build 126128, and 6.5.1 and earlier 6.x versions; VMware Player before 1.0.9 build 126128, and 2.5.1 and …
|
NVD-CWE-noinfo
|
CVE-2008-4916
|
2017-09-29 10:32 |
2009-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292196
|
- |
|
visagesoft
|
expert_pdf_viewer_activex
|
Insecure method vulnerability in VISAGESOFT eXPert PDF Viewer X ActiveX control (VSPDFViewerX.ocx) 3.0.990.0 allows remote attackers to overwrite arbitrary files via a full pathname to the savePageAs…
|
CWE-20
Improper Input Validation
|
CVE-2008-4919
|
2017-09-29 10:32 |
2008-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292197
|
- |
|
chipmunk_scripts
|
chipmunk_cms
|
board/admin/reguser.php in Chipmunk CMS 1.3 allows remote attackers to bypass authentication and gain administrator privileges via a direct request. NOTE: some of these details are obtained from thi…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-4921
|
2017-09-29 10:32 |
2008-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292198
|
- |
|
djvu
|
activex_control_for_microsoft_office_2000
|
Buffer overflow in the DjVu ActiveX Control 3.0 for Microsoft Office (DjVu_ActiveX_MSOffice.dll) allows remote attackers to execute arbitrary code via a long (1) ImageURL property, and possibly the (…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2008-4922
|
2017-09-29 10:32 |
2008-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292199
|
- |
|
mw6_technologies
|
aztec_activex
|
Multiple insecure method vulnerabilities in MW6 Technologies Aztec ActiveX control (AZTECLib.MW6Aztec, Aztec.dll) 3.0.0.1 allow remote attackers to overwrite arbitrary files via a full pathname argum…
|
NVD-CWE-noinfo
|
CVE-2008-4923
|
2017-09-29 10:32 |
2008-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292200
|
- |
|
mw6_technologies
|
1d_barcode_decoder_activex
|
Multiple insecure method vulnerabilities in MW6 Technologies 1D Barcode ActiveX control (BARCODELib.MW6Barcode, Barcode.dll) 3.0.0.1 allow remote attackers to overwrite arbitrary files via a full pat…
|
NVD-CWE-noinfo
|
CVE-2008-4924
|
2017-09-29 10:32 |
2008-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|