|
287881
|
- |
|
auracms
|
auracms
|
js/pages/pages_data.php in AuraCMS 2.2 through 2.2.2 does not perform authentication, which allows remote attackers to add, edit, and delete web content via a modified id parameter.
|
CWE-287
Improper Authentication
|
CVE-2008-3203
|
2017-10-19 10:30 |
2008-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287882
|
- |
|
tuxplanet
|
bilboblog
|
Multiple cross-site scripting (XSS) vulnerabilities in BilboBlog 0.2.1 allow remote authenticated administrators to inject arbitrary web script or HTML via the (1) content parameter to admin/update.p…
|
CWE-79
Cross-site Scripting
|
CVE-2008-3301
|
2017-10-19 10:30 |
2008-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287883
|
- |
|
tuxplanet
|
bilboblog
|
BilboBlog 0.2.1 allows remote attackers to obtain sensitive information via (1) an enable_cache=false query string to footer.php or (2) a direct request to pagination.php, which reveals the installat…
|
CWE-200
Information Exposure
|
CVE-2008-3304
|
2017-10-19 10:30 |
2008-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287884
|
- |
|
maian
|
weblog
|
admin/index.php in Maian Weblog 4.0 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitrary weblog_cookie cookie.
|
CWE-287
Improper Authentication
|
CVE-2008-3318
|
2017-10-19 10:30 |
2008-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287885
|
- |
|
maian
|
links
|
admin/index.php in Maian Links 3.1 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitrary links_cookie cookie.
|
CWE-287
Improper Authentication
|
CVE-2008-3319
|
2017-10-19 10:30 |
2008-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287886
|
- |
|
maian
|
guestbook
|
admin/index.php in Maian Guestbook 3.2 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitrary gbook_cookie cookie.
|
CWE-287
Improper Authentication
|
CVE-2008-3320
|
2017-10-19 10:30 |
2008-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287887
|
- |
|
maian_script_world
|
maian_uploader
|
admin/index.php in Maian Uploader 4.0 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitrary uploader_cookie cookie.
|
CWE-287
Improper Authentication
|
CVE-2008-3321
|
2017-10-19 10:30 |
2008-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287888
|
- |
|
maian
|
recipe
|
admin/index.php in Maian Recipe 1.2 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitrary recipe_cookie cookie.
|
CWE-287
Improper Authentication
|
CVE-2008-3322
|
2017-10-19 10:30 |
2008-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287889
|
- |
|
source_workshop
|
web_directory_script
|
SQL injection vulnerability in index.php in Web Directory Script 1.5.3 allows remote attackers to execute arbitrary SQL commands via the site parameter in an open action.
|
CWE-89
SQL Injection
|
CVE-2008-4091
|
2017-10-19 10:30 |
2008-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287890
|
- |
|
mysql_quick_admin
|
mysql_quick_admin
|
Directory traversal vulnerability in index.php in EKINdesigns MySQL Quick Admin 1.5.5 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to read and execute arbitrary files via a…
|
CWE-22
Path Traversal
|
CVE-2008-4455
|
2017-10-19 10:30 |
2008-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|