|
285221
|
- |
|
zkesoft
|
ayeview
|
AyeView 2.20 allows user-assisted attackers to cause a denial of service (application crash) via a GIF file with a malformed header.
|
NVD-CWE-noinfo
|
CVE-2008-5884
|
2018-10-12 05:56 |
2009-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285222
|
- |
|
tincan
|
phplist
|
phplist before 2.10.8 allows remote attackers to include files via unknown vectors, related to a "local file include vulnerability."
|
CWE-20
Improper Input Validation
|
CVE-2008-5887
|
2018-10-12 05:56 |
2009-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285223
|
- |
|
cfagcms
|
cfagcms
|
Multiple PHP remote file inclusion vulnerabilities in themes/default/index.php in Cant Find A Gaming CMS (CFAGCMS) 1 allow remote attackers to execute arbitrary PHP code via a URL in the (1) main and…
|
CWE-94
Code Injection
|
CVE-2008-5922
|
2018-10-12 05:56 |
2009-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285224
|
- |
|
factosystem
|
factosystem_weblog
|
Facto stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing the password via a direct request for da…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-5935
|
2018-10-12 05:56 |
2009-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285225
|
- |
|
mydyngallery
|
mydyngallery
|
SQL injection vulnerability in the Mydyngallery (com_mydyngallery) component 1.4.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the directory parameter to index.php.
|
CWE-89
SQL Injection
|
CVE-2008-5957
|
2018-10-12 05:56 |
2009-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285226
|
- |
|
impresscms
|
impresscms
|
Session fixation vulnerability in Social ImpressCMS before 1.1.1 RC1 allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.
|
CWE-287
Improper Authentication
|
CVE-2008-5964
|
2018-10-12 05:56 |
2009-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285227
|
- |
|
bmc
|
patrol_agent
|
Format string vulnerability in BMC PATROL Agent before 3.7.30 allows remote attackers to execute arbitrary code via format string specifiers in an invalid version number to TCP port 3181, which are n…
|
CWE-134
Use of Externally-Controlled Format String
|
CVE-2008-5982
|
2018-10-12 05:56 |
2009-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285228
|
- |
|
drupal
|
ajax_checklist
|
Multiple SQL injection vulnerabilities in the ajax_checklist_save function in the Ajax Checklist module 5.x before 5.x-1.1 for Drupal allow remote authenticated users, with "update ajax checklists" p…
|
CWE-89
SQL Injection
|
CVE-2008-5998
|
2018-10-12 05:56 |
2009-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285229
|
- |
|
herongyang
|
hybook
|
hyBook Guestbook Script stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing a password via a direct reque…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-6008
|
2018-10-12 05:56 |
2009-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285230
|
- |
|
bluepage
|
bluepage_cms
|
Multiple cross-site scripting (XSS) vulnerabilities in index.php in BLUEPAGE CMS 2.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) whl, (2) var_1, and (3) sear…
|
CWE-79
Cross-site Scripting
|
CVE-2008-6027
|
2018-10-12 05:56 |
2009-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|