|
287891
|
- |
|
tribiq
|
tribiq_cms
|
Directory traversal vulnerability in templates/mytribiqsite/tribal-GPL-1066/includes/header.inc.php in Tribiq CMS 5.0.10a, when register_globals is enabled and magic_quotes_gpc is disabled, allows re…
|
CWE-22
Path Traversal
|
CVE-2008-4894
|
2017-10-19 10:30 |
2008-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287892
|
- |
|
scripts_frenzy
|
article_publisher_pro
|
SQL injection vulnerability in admin/admin.php in Article Publisher Pro 1.5 allows remote attackers to execute arbitrary SQL commands via the username parameter.
|
CWE-89
SQL Injection
|
CVE-2008-4901
|
2017-10-19 10:30 |
2008-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287893
|
- |
|
scripts_frenzy
|
article_publisher_pro
|
SQL injection vulnerability in contact_author.php in Article Publisher Pro 1.5 allows remote attackers to execute arbitrary SQL commands via the userid parameter.
|
CWE-89
SQL Injection
|
CVE-2008-4902
|
2017-10-19 10:30 |
2008-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287894
|
- |
|
develop_it_easy
|
membership_system
|
Multiple SQL injection vulnerabilities in Develop It Easy Membership System 1.3 allow remote attackers to execute arbitrary SQL commands via the (1) email and (2) password parameters to customer_logi…
|
CWE-89
SQL Injection
|
CVE-2008-5054
|
2017-10-19 10:30 |
2008-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287895
|
- |
|
preproject
|
pre_simple_cms
|
SQL injection vulnerability in siteadmin/loginsucess.php in Pre Simple CMS allows remote attackers to execute arbitrary SQL commands via the user parameter, as reachable from siteadmin/adminlogin.php…
|
CWE-89
SQL Injection
|
CVE-2008-5058
|
2017-10-19 10:30 |
2008-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287896
|
- |
|
deeserver
|
panuwat_promoteweb_mysql
|
SQL injection vulnerability in go.php in Panuwat PromoteWeb MySQL, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2008-5069
|
2017-10-19 10:30 |
2008-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287897
|
- |
|
opera
|
opera
|
Heap-based buffer overflow in Opera 9.62 on Windows allows remote attackers to execute arbitrary code via a long file:// URI. NOTE: this might overlap CVE-2008-5680.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2008-5178
|
2017-10-19 10:30 |
2008-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287898
|
- |
|
syndeocms
|
syndeocms
|
Cross-site scripting (XSS) vulnerability in index.php in Fred Stuurman SyndeoCMS 2.6.0 allows remote attackers to inject arbitrary web script or HTML via the section parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2008-5271
|
2017-10-19 10:30 |
2008-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287899
|
- |
|
syndeocms
|
syndeocms
|
Solution:
Update to version 2.6.02.
http://sourceforge.net/project/showfi...ckage_id=220740&release_id=610817
|
CWE-79
Cross-site Scripting
|
CVE-2008-5271
|
2017-10-19 10:30 |
2008-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287900
|
- |
|
activewebsoftwares
|
activevotes
|
SQL injection vulnerability in VoteHistory.asp in ActiveWebSoftwares ActiveVotes 2.2 allows remote attackers to execute arbitrary SQL commands via the AccountID parameter.
|
CWE-89
SQL Injection
|
CVE-2008-5365
|
2017-10-19 10:30 |
2008-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|