|
293551
|
- |
|
bpowerhouse
|
mini_cms
|
Multiple directory traversal vulnerabilities in index.php in Mini CMS 1.0.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) page and (2) admin parame…
|
CWE-22
Path Traversal
|
CVE-2008-5593
|
2017-09-29 10:32 |
2008-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293552
|
- |
|
bpowerhouse
|
mini_blog
|
Multiple directory traversal vulnerabilities in index.php in Mini Blog 1.0.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) page and (2) admin param…
|
CWE-22
Path Traversal
|
CVE-2008-5594
|
2017-09-29 10:32 |
2008-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293553
|
- |
|
aspapps
|
asp_autodealer
|
SQL injection vulnerability in detail.asp in ASP AutoDealer allows remote attackers to execute arbitrary SQL commands via the ID parameter.
|
CWE-89
SQL Injection
|
CVE-2008-5595
|
2017-09-29 10:32 |
2008-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293554
|
- |
|
dotnetindex
|
ikon_admanager
|
Ikon AdManager 2.1 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for i…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-5596
|
2017-09-29 10:32 |
2008-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293555
|
- |
|
cold_bbs
|
cold_bbs
|
Cold BBS stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for db/cforum.mdb.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-5597
|
2017-09-29 10:32 |
2008-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293556
|
- |
|
phpmygallery
|
phpmygallery
|
Directory traversal vulnerability in index.php in PHPmyGallery 1.51 gold allows remote attackers to list arbitrary directories via a .. (dot dot) in the group parameter.
|
CWE-22
Path Traversal
|
CVE-2008-5598
|
2017-09-29 10:32 |
2008-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293557
|
- |
|
merlix
|
teamworx_server
|
SQL injection vulnerability in default.asp in Merlix Teamworx Server allows remote attackers to execute arbitrary SQL commands via the password parameter (aka passwd field) in a login action. NOTE: …
|
CWE-89
SQL Injection
|
CVE-2008-5599
|
2017-09-29 10:32 |
2008-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293558
|
- |
|
merlix
|
teamworx_server
|
Merlix Teamworx Server stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for teamworx.…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-5600
|
2017-09-29 10:32 |
2008-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293559
|
- |
|
robs-projects
|
asp_user_engine
|
User Engine Lite ASP stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for users.mdb.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-5601
|
2017-09-29 10:32 |
2008-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293560
|
- |
|
natterchat
|
natterchat
|
Natterchat 1.12 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for natterchat112.md…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-5602
|
2017-09-29 10:32 |
2008-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|