|
293141
|
- |
|
netenberg
|
fantastico_de_luxe
|
Directory traversal vulnerability in includes/xml.php in the Netenberg Fantastico De Luxe module before 2.10.4 r19 for cPanel, when cPanel PHP Register Globals is enabled, allows remote authenticated…
|
CWE-22
Path Traversal
|
CVE-2008-4181
|
2017-09-29 10:32 |
2008-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293142
|
- |
|
integramod
|
integramod
|
IntegraMOD 1.4.x stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a backup via a direct request to a backup/backup-yyyy-dd-m…
|
CWE-200
Information Exposure
|
CVE-2008-4183
|
2017-09-29 10:32 |
2008-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293143
|
- |
|
webcms
|
webcms_portal_edition
|
SQL injection vulnerability in index.php in webCMS Portal Edition allows remote attackers to execute arbitrary SQL commands via the id parameter in a documentos action, a different vector than CVE-20…
|
CWE-89
SQL Injection
|
CVE-2008-4185
|
2017-09-29 10:32 |
2008-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293144
|
- |
|
proactive_cms
|
proactive_cms
|
Directory traversal vulnerability in index.php in ProActive CMS allows remote attackers to read arbitrary files via a .. (dot dot) in the template parameter.
|
CWE-22
Path Traversal
|
CVE-2008-4187
|
2017-09-29 10:32 |
2008-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293145
|
- |
|
alt-n
|
securitygateway
|
Stack-based buffer overflow in SecurityGateway.dll in Alt-N Technologies SecurityGateway 1.0.1 allows remote attackers to execute arbitrary code via a long username parameter.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2008-4193
|
2017-09-29 10:32 |
2008-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293146
|
- |
|
gonafish
|
linkscaffepro
|
SQL injection vulnerability in index.php in Gonafish LinksCaffePRO 4.5 allows remote attackers to execute arbitrary SQL commands via the idd parameter in a deadlink action.
|
CWE-89
SQL Injection
|
CVE-2008-4202
|
2017-09-29 10:32 |
2008-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293147
|
- |
|
czaries
|
czarnews
|
SQL injection vulnerability in cn_users.php in CzarNews 1.20 and earlier allows remote attackers to execute arbitrary SQL commands via a recook cookie.
|
CWE-89
SQL Injection
|
CVE-2008-4203
|
2017-09-29 10:32 |
2008-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293148
|
- |
|
softacid
|
hotel_reservation_system
|
SQL injection vulnerability in city.asp in SoftAcid Hotel Reservation System (HRS) allows remote attackers to execute arbitrary SQL commands via the city parameter.
|
CWE-89
SQL Injection
|
CVE-2008-4204
|
2017-09-29 10:32 |
2008-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293149
|
- |
|
xmlsoft
|
libxml
|
Integer overflow in the xmlBufferResize function in libxml2 2.7.2 allows context-dependent attackers to cause a denial of service (infinite loop) via a large XML document.
|
CWE-189
Numeric Errors
|
CVE-2008-4225
|
2017-09-29 10:32 |
2008-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293150
|
- |
|
xmlsoft
|
libxml
|
Integer overflow in the xmlSAX2Characters function in libxml2 2.7.2 allows context-dependent attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a large …
|
CWE-399
Resource Management Errors
|
CVE-2008-4226
|
2017-09-29 10:32 |
2008-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|