|
285181
|
- |
|
phpeppershop
|
phpeppershop
|
Multiple cross-site scripting (XSS) vulnerabilities in PHPepperShop 1.4 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) index.php or (2) shop/kontakt.php, or (3…
|
CWE-79
Cross-site Scripting
|
CVE-2008-5569
|
2018-10-12 05:56 |
2008-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285182
|
- |
|
proclanmanager
|
pro_clan_manager
|
Session fixation vulnerability in Pro Clan Manager 0.4.2 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.
|
CWE-287
Improper Authentication
|
CVE-2008-5575
|
2018-10-12 05:56 |
2008-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285183
|
- |
|
mini-pub
|
mini-pub
|
Absolute path traversal vulnerability in mini-pub.php/front-end/cat.php in mini-pub 0.3 allows remote attackers to read arbitrary files via a full pathname in the sFileName parameter.
|
CWE-22
Path Traversal
|
CVE-2008-5579
|
2018-10-12 05:56 |
2008-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285184
|
- |
|
mini-pub
|
mini-pub
|
mini-pub.php/front-end/cat.php in mini-pub 0.3 allows remote attackers to execute arbitrary commands via shell metacharacters in the sFileName argument.
|
CWE-20
Improper Input Validation
|
CVE-2008-5580
|
2018-10-12 05:56 |
2008-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285185
|
- |
|
mini-pub
|
mini-pub
|
PHP remote file inclusion vulnerability in mini-pub.php/front-end/img.php in mini-pub 0.3 allows remote attackers to execute arbitrary PHP code via a URL in the sFileName parameter.
|
CWE-20
Improper Input Validation
|
CVE-2008-5581
|
2018-10-12 05:56 |
2008-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285186
|
- |
|
mplayer
|
mplayer
|
Stack-based buffer overflow in the demux_open_vqf function in libmpdemux/demux_vqf.c in MPlayer 1.0 rc2 before r28150 allows remote attackers to execute arbitrary code via a malformed TwinVQ file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2008-5616
|
2018-10-12 05:56 |
2008-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285187
|
- |
|
roundcube
|
webmail
|
html2text.php in Chuggnutt HTML to Text Converter, as used in PHPMailer before 5.2.10, RoundCube Webmail (roundcubemail) 0.2-1.alpha and 0.2-3.beta, Mahara, and AtMail Open 1.03, allows remote attack…
|
CWE-94
Code Injection
|
CVE-2008-5619
|
2018-10-12 05:56 |
2008-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285188
|
- |
|
php
|
php
|
PHP 5 before 5.2.7 does not properly initialize the page_uid and page_gid global variables for use by the SAPI php_getuid function, which allows context-dependent attackers to bypass safe_mode restri…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-5624
|
2018-10-12 05:56 |
2008-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285189
|
- |
|
php
|
php
|
PHP 5 before 5.2.7 does not enforce the error_log safe_mode restrictions when safe_mode is enabled through a php_admin_flag setting in httpd.conf, which allows context-dependent attackers to write to…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-5625
|
2018-10-12 05:56 |
2008-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285190
|
- |
|
php
|
php
|
Directory traversal vulnerability in the ZipArchive::extractTo function in PHP 5.2.6 and earlier allows context-dependent attackers to write arbitrary files via a ZIP file with a file whose name cont…
|
CWE-22
Path Traversal
|
CVE-2008-5658
|
2018-10-12 05:56 |
2008-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|