|
285231
|
- |
|
mapcal
|
mapcal
|
SQL injection vulnerability in index.php in MapCal 0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter in an editevent action, possibly related to dsp_editevent.php.
|
CWE-89
SQL Injection
|
CVE-2008-6038
|
2018-10-12 05:56 |
2009-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285232
|
- |
|
bluepage
|
bluepage_cms
|
Session fixation vulnerability in BLUEPAGE CMS 2.5 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.
|
CWE-287
Improper Authentication
|
CVE-2008-6039
|
2018-10-12 05:56 |
2009-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285233
|
- |
|
phpprobid
|
php_pro_bid
|
Multiple SQL injection vulnerabilities in PHP Pro Bid (PPB) 6.04 allow remote attackers to execute arbitrary SQL commands via the (1) order_field and (2) order_type parameters to categories.php and u…
|
CWE-89
SQL Injection
|
CVE-2008-6043
|
2018-10-12 05:56 |
2009-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285234
|
- |
|
metalinks
|
metacart
|
MetaCart Free stores metacart.mdb under the web root with insufficient access control, which allows remote attackers to obtain usernames and passwords via a direct request.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-6051
|
2018-10-12 05:56 |
2009-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285235
|
- |
|
ex-designs
|
world_recipe
|
Multiple cross-site scripting (XSS) vulnerabilities in World Recipe 2.11 allow remote attackers to inject arbitrary web script or HTML via the (1) n parameter to emailrecipe.aspx, (2) id parameter to…
|
CWE-79
Cross-site Scripting
|
CVE-2008-6056
|
2018-10-12 05:56 |
2009-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285236
|
- |
|
infosoftglobal
|
fusion_charts
|
Cross-site scripting (XSS) vulnerability in ActionScript in arbitrary Shockwave Flash (SWF) files created by InfoSoft FusionCharts allows remote attackers to inject arbitrary additional SWF content v…
|
CWE-79
Cross-site Scripting
|
CVE-2008-6060
|
2018-10-12 05:56 |
2009-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285237
|
- |
|
techsmith
|
camtasia_studio
|
Cross-site scripting (XSS) vulnerability in ActionScript in arbitrary Shockwave Flash (SWF) controller files created by Techsmith Camtasia Studio before 5 allows remote attackers to inject arbitrary …
|
CWE-79
Cross-site Scripting
|
CVE-2008-6061
|
2018-10-12 05:56 |
2009-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285238
|
- |
|
adobe
|
dreamweaver
|
Cross-site scripting (XSS) vulnerability in ActionScript in arbitrary Shockwave Flash (SWF) files created by Adobe Dreamweaver, when the Insert Flash Video feature is used, allows remote attackers to…
|
CWE-79
Cross-site Scripting
|
CVE-2008-6062
|
2018-10-12 05:56 |
2009-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285239
|
- |
|
microsoft
|
word
|
Microsoft Word 2007, when the "Save as PDF" add-on is enabled, places an absolute pathname in the Subject field during an "Email as PDF" operation, which allows remote attackers to obtain sensitive i…
|
CWE-200
Information Exposure
|
CVE-2008-6063
|
2018-10-12 05:56 |
2009-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285240
|
- |
|
123flashchat
|
echat_plugin
|
SQL injection vulnerability in e107chat.php in the eChat plugin 4.2 for e107, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the nick parameter.
|
CWE-89
SQL Injection
|
CVE-2008-6069
|
2018-10-12 05:56 |
2009-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|