|
292161
|
- |
|
4xem d-link vivotek
|
vatctrl_class mpeg4_shm_audio_control rtsp_mpeg4_sp_control
|
Stack-based buffer overflow in VATDecoder.VatCtrl.1 ActiveX control in (1) 4xem VatCtrl Class (VATDecoder.dll 1.0.0.27 and 1.0.0.51), (2) D-Link MPEG4 SHM Audio Control (VAPGDecoder.dll 1.7.0.5), (3)…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2008-4771
|
2017-09-29 10:32 |
2008-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292162
|
- |
|
questwork
|
questcms
|
SQL injection vulnerability in main/main.php in QuestCMS allows remote attackers to execute arbitrary SQL commands via the obj parameter.
|
CWE-89
SQL Injection
|
CVE-2008-4772
|
2017-09-29 10:32 |
2008-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292163
|
- |
|
questwork
|
questcms
|
Directory traversal vulnerability in main/main.php in QuestCMS allows remote attackers to read arbitrary local files via a .. (dot dot) in the theme parameter.
|
CWE-22
Path Traversal
|
CVE-2008-4773
|
2017-09-29 10:32 |
2008-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292164
|
- |
|
questwork
|
questcms
|
Cross-site scripting (XSS) vulnerability in main/main.php in QuestCMS allows remote attackers to inject arbitrary web script or HTML via the cx parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2008-4774
|
2017-09-29 10:32 |
2008-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292165
|
- |
|
tguzip
|
tguzip
|
Stack-based buffer overflow in TUGzip 3.5.0.0 allows remote attackers to denial of service (crash) or execute arbitrary code via a long filename in a .zip file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2008-4779
|
2017-09-29 10:32 |
2008-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292166
|
- |
|
easy-script
|
myforum
|
Directory traversal vulnerability in admin/centre.php in MyForum 1.3, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal se…
|
CWE-22
Path Traversal
|
CVE-2008-4780
|
2017-09-29 10:32 |
2008-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292167
|
- |
|
easy-script
|
myktools
|
Directory traversal vulnerability in update.php in MyKtools 2.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the langage parameter.
|
CWE-22
Path Traversal
|
CVE-2008-4781
|
2017-09-29 10:32 |
2008-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292168
|
- |
|
aiocp
|
aiocp
|
SQL injection vulnerability in public/code/cp_polls_results.php in All In One Control Panel (AIOCP) 1.4 allows remote attackers to execute arbitrary SQL commands via the poll_id parameter.
|
CWE-89
SQL Injection
|
CVE-2008-4782
|
2017-09-29 10:32 |
2008-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292169
|
- |
|
easy-script
|
tlads
|
tlAds 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the tlAds_login cookie to "admin."
|
CWE-287
Improper Authentication
|
CVE-2008-4783
|
2017-09-29 10:32 |
2008-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292170
|
- |
|
aflog
|
aflog
|
aflog 1.01 allows remote attackers to bypass authentication and gain administrative access by setting the aflog_auth_a cookie to "A" or "O" in (1) edit_delete.php, (2) edit_cat.php, (3) edit_lock.php…
|
CWE-287
Improper Authentication
|
CVE-2008-4784
|
2017-09-29 10:32 |
2008-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|