|
292151
|
- |
|
scripts-for-sites
|
ez_forum
|
SQL injection vulnerability in forum.php in Scripts for Sites (SFS) Ez Forum allows remote attackers to execute arbitrary SQL commands via the forum parameter.
|
CWE-89
SQL Injection
|
CVE-2008-4754
|
2017-09-29 10:32 |
2008-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292152
|
- |
|
pozscripts
|
classified_auctions_script
|
SQL injection vulnerability in gotourl.php in PozScripts Classified Auctions Script allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2008-4755
|
2017-09-29 10:32 |
2008-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292153
|
- |
|
php-daily
|
php-daily
|
Cross-site scripting (XSS) vulnerability in add_prest_date.php in PHP-Daily allows remote attackers to inject arbitrary web script or HTML via the date parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2008-4756
|
2017-09-29 10:32 |
2008-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292154
|
- |
|
php-daily
|
php-daily
|
Multiple SQL injection vulnerabilities in PHP-Daily allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to (a) add_postit.php (b) delete.php, and (c) mod_prest_date.php;…
|
CWE-89
SQL Injection
|
CVE-2008-4757
|
2017-09-29 10:32 |
2008-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292155
|
- |
|
php-daily
|
php-daily
|
Directory traversal vulnerability in download_file.php in PHP-Daily allows remote attackers to read arbitrary local files via a .. (dot dot) in the fichier parameter.
|
CWE-22
Path Traversal
|
CVE-2008-4758
|
2017-09-29 10:32 |
2008-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292156
|
- |
|
buzzscripts
|
buzzywall
|
Directory traversal vulnerability in download.php in BuzzyWall 1.3.1 allows remote attackers to read arbitrary local files via a .. (dot dot) in the id parameter.
|
CWE-22
Path Traversal
|
CVE-2008-4759
|
2017-09-29 10:32 |
2008-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292157
|
- |
|
graphiks
|
myforum
|
SQL injection vulnerability in lecture.php in Graphiks MyForum 1.3, when register_globals is enabled, allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2008-4760
|
2017-09-29 10:32 |
2008-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292158
|
- |
|
extplorer
|
com_extplorer
|
Directory traversal vulnerability in the eXtplorer module (com_extplorer) 2.0.0 RC2 and earlier in Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the dir parameter in a…
|
CWE-22
Path Traversal
|
CVE-2008-4764
|
2017-09-29 10:32 |
2008-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292159
|
- |
|
oscommerce
|
poll_booth
|
SQL injection vulnerability in pollBooth.php in osCommerce Poll Booth Add-On 2.0 allows remote attackers to execute arbitrary SQL commands via the pollID parameter in a results operation. NOTE: this…
|
CWE-89
SQL Injection
|
CVE-2008-4765
|
2017-09-29 10:32 |
2008-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292160
|
- |
|
realvnc
|
realvnc
|
The CMsgReader::readRect function in the VNC Viewer component in RealVNC VNC Free Edition 4.0 through 4.1.2, Enterprise Edition E4.0 through E4.4.2, and Personal Edition P4.0 through P4.4.2 allows re…
|
CWE-20
Improper Input Validation
|
CVE-2008-4770
|
2017-09-29 10:32 |
2009-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|