|
293181
|
- |
|
kasseler-cms
|
kasseler_cms
|
Multiple SQL injection vulnerabilities in Kasseler CMS 1.1.0 and 1.2.0 allow remote attackers to execute arbitrary SQL commands via (1) the nid parameter to index.php in a View action to the News mod…
|
CWE-89
SQL Injection
|
CVE-2008-4356
|
2017-09-29 10:32 |
2008-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293182
|
- |
|
powie
|
plink
|
SQL injection vulnerability in linkto.php in Powie pLink 2.07 allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2008-4357
|
2017-09-29 10:32 |
2008-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293183
|
- |
|
powerportal
|
powerportal
|
Directory traversal vulnerability in PowerPortal 2.0.13 allows remote attackers to list and possibly read arbitrary files via a .. (dot dot) in the path parameter to the default URI.
|
CWE-22
Path Traversal
|
CVE-2008-4361
|
2017-09-29 10:32 |
2008-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293184
|
- |
|
deslock
|
deslock
|
The Virtual Token driver (vdlptokn.sys) 1.0.2.43 in DESlock+ 3.2.7 allows local users to cause a denial of service (system crash) via a crafted IOCTL request to \Device\DLPTokenWalter0.
|
CWE-399
Resource Management Errors
|
CVE-2008-4362
|
2017-09-29 10:32 |
2008-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293185
|
- |
|
deslock
|
deslock
|
DLMFENC.sys 1.0.0.28 in DESlock+ 3.2.7 allows local users to cause a denial of service (system crash) or potentially execute arbitrary code via a certain DLMFENC_IOCTL request to \\.\DLKPFSD_Device t…
|
CWE-20
Improper Input Validation
|
CVE-2008-4363
|
2017-09-29 10:32 |
2008-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293186
|
- |
|
camera_life
|
camera_life
|
Unrestricted file upload vulnerability in the image upload component in Camera Life 2.6.2b4 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extensio…
|
CWE-20
Improper Input Validation
|
CVE-2008-4366
|
2017-09-29 10:32 |
2008-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293187
|
- |
|
availscript
|
availscript_photo_album
|
SQL injection vulnerability in pics.php in Availscript Photo Album allows remote attackers to execute arbitrary SQL commands via the sid parameter.
|
CWE-89
SQL Injection
|
CVE-2008-4369
|
2017-09-29 10:32 |
2008-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293188
|
- |
|
availscript
|
availscript_photo_album
|
Multiple cross-site scripting (XSS) vulnerabilities in Availscript Photo Album allow remote attackers to inject arbitrary web script or HTML via the (1) sid parameter to pics.php and the (2) a parame…
|
CWE-79
Cross-site Scripting
|
CVE-2008-4370
|
2017-09-29 10:32 |
2008-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293189
|
- |
|
availscript
|
availscript_article_script
|
SQL injection vulnerability in articles.php in AvailScript Article Script allows remote attackers to execute arbitrary SQL commands via the aIDS parameter.
|
CWE-89
SQL Injection
|
CVE-2008-4371
|
2017-09-29 10:32 |
2008-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293190
|
- |
|
availscript
|
availscript_article_script
|
Cross-site scripting (XSS) vulnerability in articles.php in AvailScript Article Script allows remote attackers to inject arbitrary web script or HTML via the aIDS parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2008-4372
|
2017-09-29 10:32 |
2008-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|