|
293481
|
- |
|
littlecms
|
lcms little_cms_color_engine
|
Buffer overflow in the ReadEmbeddedTextTag function in src/cmsio1.c in Little cms color engine (aka lcms) before 1.16 allows attackers to have an unknown impact via vectors related to a length parame…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2008-5316
|
2017-09-29 10:32 |
2008-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293482
|
- |
|
e107
|
e107
|
SQL injection vulnerability in usersettings.php in e107 0.7.13 and earlier allows remote authenticated users to execute arbitrary SQL commands via the ue[] parameter.
|
CWE-89
SQL Injection
|
CVE-2008-5320
|
2017-09-29 10:32 |
2008-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293483
|
- |
|
xoops_hocasi
|
gesgaleri
|
SQL injection vulnerability in index.php in GesGaleri, a module for XOOPS, allows remote attackers to execute arbitrary SQL commands via the no parameter.
|
CWE-89
SQL Injection
|
CVE-2008-5321
|
2017-09-29 10:32 |
2008-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293484
|
- |
|
easy-script
|
wysi_wiki_wyg
|
Wysi Wiki Wyg 1.0 allows remote attackers to obtain system information via an invalid categup parameter to index.php, which calls the phpinfo function.
|
CWE-200
Information Exposure
|
CVE-2008-5322
|
2017-09-29 10:32 |
2008-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293485
|
- |
|
easy-script
|
wysi_wiki_wyg
|
Cross-site scripting (XSS) vulnerability in index.php in Wysi Wiki Wyg 1.0 allows remote attackers to inject arbitrary web script or HTML via the s parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2008-5323
|
2017-09-29 10:32 |
2008-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293486
|
- |
|
pie
|
pie
|
Multiple PHP remote file inclusion vulnerabilities in Pie 0.5.3 allow remote attackers to execute arbitrary PHP code via a URL in the (1) lib parameter to files in lib/action/ including (a) alias.php…
|
CWE-94
Code Injection
|
CVE-2008-5332
|
2017-09-29 10:32 |
2008-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293487
|
- |
|
nitrotech
|
nitrotech
|
SQL injection vulnerability in members.php in NitroTech 0.0.3a allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2008-5333
|
2017-09-29 10:32 |
2008-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293488
|
- |
|
nitrotech
|
nitrotech
|
PHP remote file inclusion vulnerability in includes/common.php in NitroTech 0.0.3a allows remote attackers to execute arbitrary PHP code via a URL in the root parameter.
|
CWE-94
Code Injection
|
CVE-2008-5334
|
2017-09-29 10:32 |
2008-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293489
|
- |
|
php-fusion
|
php-fusion
|
SQL injection vulnerability in messages.php in PHP-Fusion 6.01.15 and 7.00.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the subject and msg_send…
|
CWE-89
SQL Injection
|
CVE-2008-5335
|
2017-09-29 10:32 |
2008-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293490
|
- |
|
multimania
|
bandsite_portal_system bandwebsite
|
SQL injection vulnerability in lyrics.php in Bandwebsite (aka Bandsite portal system) 1.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2008-5337
|
2017-09-29 10:32 |
2008-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|