|
293801
|
- |
|
lokicms
|
lokicms
|
Directory traversal vulnerability in index.php in LokiCMS 0.3.4 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to check for the existence of arbitrary files via a .. (dot dot…
|
CWE-22
Path Traversal
|
CVE-2008-5965
|
2017-09-29 10:32 |
2009-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293802
|
- |
|
globsy
|
globsy
|
globsy_edit.php in Globsy 1.0 and earlier allows remote attackers to create or overwrite arbitrary files via a filename in the file parameter and file contents in the data parameter.
|
CWE-20
Improper Input Validation
|
CVE-2008-5966
|
2017-09-29 10:32 |
2009-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293803
|
- |
|
sunbyte
|
e-flower
|
SQL injection vulnerability in popupproduct.php in Sunbyte e-Flower allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2008-5969
|
2017-09-29 10:32 |
2009-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293804
|
- |
|
activewebsoftwares
|
active_business_directory
|
SQL injection vulnerability in default.asp in Active Business Directory 2 allows remote attackers to execute arbitrary SQL commands via the catid parameter.
|
CWE-89
SQL Injection
|
CVE-2008-5972
|
2017-09-29 10:32 |
2009-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293805
|
- |
|
activewebsoftwares
|
active_web_mail
|
SQL injection vulnerability in login.aspx in Active Web Mail 4.0 allows remote attackers to execute arbitrary SQL commands via the password parameter.
|
CWE-89
SQL Injection
|
CVE-2008-5973
|
2017-09-29 10:32 |
2009-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293806
|
- |
|
activewebsoftwares
|
active_price_comparison
|
Multiple SQL injection vulnerabilities in login.aspx in Active Price Comparison 4.0 allow remote attackers to execute arbitrary SQL commands via the (1) password and (2) username fields.
|
CWE-89
SQL Injection
|
CVE-2008-5974
|
2017-09-29 10:32 |
2009-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293807
|
- |
|
ocean12_technologies
|
mailing_list_manager
|
Multiple SQL injection vulnerabilities in Ocean12 Mailing List Manager Gold allow remote attackers to execute arbitrary SQL commands via the Email parameter to (1) default.asp and (2) s_edit.asp.
|
CWE-89
SQL Injection
|
CVE-2008-5978
|
2017-09-29 10:32 |
2009-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293808
|
- |
|
ocean12_technologies
|
mailing_list_manager
|
Cross-site scripting (XSS) vulnerability in default.asp in Ocean12 Mailing List Manager Gold allows remote attackers to inject arbitrary web script or HTML via the Email parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2008-5979
|
2017-09-29 10:32 |
2009-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293809
|
- |
|
ocean12_technologies
|
mailing_list_manager
|
Ocean12 Mailing List Manager Gold stores sensitive data under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for o12mail.mdb.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-5980
|
2017-09-29 10:32 |
2009-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293810
|
- |
|
pacosdrivers
|
pacpoll
|
PacPoll 4.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for (1) poll.mdb or (2) poll97.…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-5981
|
2017-09-29 10:32 |
2009-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|