|
294351
|
- |
|
hans_oesterholt
|
cmme
|
Multiple cross-site scripting (XSS) vulnerabilities in statistics.php in Content Management Made Easy (CMME) 1.12 allow remote attackers to inject arbitrary web script or HTML via the (1) page and (2…
|
CWE-79
Cross-site Scripting
|
CVE-2008-3923
|
2017-09-29 10:31 |
2008-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294352
|
- |
|
hans_oesterholt
|
cmme
|
The "Make a backup" functionality in Content Management Made Easy (CMME) 1.12 stores sensitive information under the web root with insufficient access control, which allows remote attackers to discov…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-3924
|
2017-09-29 10:31 |
2008-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294353
|
- |
|
hans_oesterholt
|
cmme
|
Cross-site request forgery (CSRF) vulnerability in admin.php in Content Management Made Easy (CMME) 1.12 allows remote attackers to trigger the logout of an administrative user via a logout action.
|
CWE-352
Origin Validation Error
|
CVE-2008-3925
|
2017-09-29 10:31 |
2008-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294354
|
- |
|
hans_oesterholt
|
cmme
|
Multiple directory traversal vulnerabilities in Content Management Made Easy (CMME) 1.12 allow remote attackers to (1) read arbitrary files via a .. (dot dot) in the env parameter in a weblog action …
|
CWE-22
Path Traversal
|
CVE-2008-3926
|
2017-09-29 10:31 |
2008-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294355
|
- |
|
ezonescripts
|
living_local
|
SQL injection vulnerability in listtest.php in eZoneScripts Living Local 1.1 allows remote attackers to execute arbitrary SQL commands via the r parameter.
|
CWE-89
SQL Injection
|
CVE-2008-3943
|
2017-09-29 10:31 |
2008-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294356
|
- |
|
discountedscripts
|
acg_ptp
|
SQL injection vulnerability in index.php in ACG-PTP 1.0.6 allows remote attackers to execute arbitrary SQL commands via the adid parameter in an adorder action.
|
CWE-89
SQL Injection
|
CVE-2008-3944
|
2017-09-29 10:31 |
2008-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294357
|
- |
|
source_workshop
|
words_tag_script
|
SQL injection vulnerability in index.php in Words tag 1.2 allows remote attackers to execute arbitrary SQL commands via the word parameter in a claim action.
|
CWE-89
SQL Injection
|
CVE-2008-3945
|
2017-09-29 10:31 |
2008-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294358
|
- |
|
vastal
|
agent_zone
|
SQL injection vulnerability in view_ann.php in Vastal I-Tech Agent Zone (aka The Real Estate Script) allows remote attackers to execute arbitrary SQL commands via the ann_id parameter.
|
CWE-89
SQL Injection
|
CVE-2008-3951
|
2017-09-29 10:31 |
2008-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294359
|
- |
|
editeurscripts_esfaq
|
2.0
|
SQL injection vulnerability in questions.php in EsFaq 2.0 allows remote attackers to execute arbitrary SQL commands via the idcat parameter.
|
CWE-89
SQL Injection
|
CVE-2008-3952
|
2017-09-29 10:31 |
2008-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294360
|
- |
|
vastal
|
shaadi_zone
|
SQL injection vulnerability in keyword_search_action.php in Vastal I-Tech Shaadi Zone 1.0.9 allows remote attackers to execute arbitrary SQL commands via the tage parameter.
|
CWE-89
SQL Injection
|
CVE-2008-3953
|
2017-09-29 10:31 |
2008-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|