|
293531
|
- |
|
phpmultiplenewsletters
|
phpmultiplenewsletters
|
Cross-site scripting (XSS) vulnerability in index.php in Triangle Solutions PHP Multiple Newsletters 2.7 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.
|
CWE-79
Cross-site Scripting
|
CVE-2008-5566
|
2017-09-29 10:32 |
2008-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293532
|
- |
|
bonzacart
|
bonza_cart
|
Cross-site request forgery (CSRF) vulnerability in admin/ad_settings.php in Bonza Cart 1.10 and earlier allows remote attackers to change the admin password via a logout action in conjunction with th…
|
CWE-352
Origin Validation Error
|
CVE-2008-5567
|
2017-09-29 10:32 |
2008-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293533
|
- |
|
ipn-mate
|
ipn_pro_3
|
Cross-site request forgery (CSRF) vulnerability in admin/settings.php in IPN Pro 3 1.44 and earlier allows remote attackers to change the admin password via a logout action in conjunction with the ad…
|
CWE-352
Origin Validation Error
|
CVE-2008-5568
|
2017-09-29 10:32 |
2008-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293534
|
- |
|
php_multiple_newsletters
|
php_multiple_newsletters
|
Directory traversal vulnerability in index.php in PHP Multiple Newsletters 2.7, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot d…
|
CWE-22
Path Traversal
|
CVE-2008-5570
|
2017-09-29 10:32 |
2008-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293535
|
- |
|
dotnetindex
|
professional_download_assistant
|
SQL injection vulnerability in admin/login.asp in Professional Download Assistant 0.1 allows remote attackers to execute arbitrary SQL commands via the (1) uname parameter (aka user field) or the (2)…
|
CWE-89
SQL Injection
|
CVE-2008-5571
|
2017-09-29 10:32 |
2008-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293536
|
- |
|
dotnetindex
|
professional_download_assistant
|
Professional Download Assistant 0.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-5572
|
2017-09-29 10:32 |
2008-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293537
|
- |
|
adcomplete
|
poll_pro
|
SQL injection vulnerability in the login feature in Poll Pro 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) Password and (2) username parameters.
|
CWE-89
SQL Injection
|
CVE-2008-5573
|
2017-09-29 10:32 |
2008-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293538
|
- |
|
unscripts
|
webmaster_marketplace
|
SQL injection vulnerability in member.php in Webmaster Marketplace allows remote attackers to execute arbitrary SQL commands via the u parameter.
|
CWE-89
SQL Injection
|
CVE-2008-5574
|
2017-09-29 10:32 |
2008-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293539
|
- |
|
scssboard
|
scssboard
|
admin/forums.php in sCssBoard 1.0, 1.1, 1.11, and 1.12 allows remote attackers to bypass authentication and gain administrative access via a large value of the current_user[users_level] parameter.
|
CWE-287
Improper Authentication
|
CVE-2008-5576
|
2017-09-29 10:32 |
2008-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293540
|
- |
|
scssboard
|
scssboard
|
PHP remote file inclusion vulnerability in index.php in sCssBoard 1.0, 1.1, 1.11, and 1.12 allows remote attackers to execute arbitrary PHP code via a URL in the inc_function parameter.
|
CWE-94
Code Injection
|
CVE-2008-5577
|
2017-09-29 10:32 |
2008-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|