|
292171
|
- |
|
e107
|
alternate_profiles_plugin
|
SQL injection vulnerability in newuser.php in the alternate_profiles plugin, possibly 0.2, for e107 allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2008-4785
|
2017-09-29 10:32 |
2008-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292172
|
- |
|
e107
|
easyshop_plugin
|
SQL injection vulnerability in easyshop.php in the EasyShop plugin for e107 allows remote attackers to execute arbitrary SQL commands via the category_id parameter.
|
CWE-89
SQL Injection
|
CVE-2008-4786
|
2017-09-29 10:32 |
2008-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292173
|
- |
|
sepal
|
spboard
|
board.cgi in Sepal SPBOARD 4.5 allows remote attackers to execute arbitrary commands via shell metacharacters in the file parameter during a down_file action.
|
NVD-CWE-noinfo
|
CVE-2008-4873
|
2017-09-29 10:32 |
2008-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292174
|
- |
|
mywebcards
|
webcards
|
SQL injection vulnerability in admin.php in WebCards 1.3, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the user parameter. NOTE: some of these det…
|
CWE-89
SQL Injection
|
CVE-2008-4877
|
2017-09-29 10:32 |
2008-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292175
|
- |
|
mywebcards
|
webcards
|
Unrestricted file upload vulnerability in the "Add Image Macro" feature in WebCards 1.3 allows remote authenticated administrators to execute arbitrary code by uploading a file with an executable ext…
|
CWE-20
Improper Input Validation
|
CVE-2008-4878
|
2017-09-29 10:32 |
2008-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292176
|
- |
|
maran
|
php_shop
|
SQL injection vulnerability in prod.php in Maran PHP Shop allows remote attackers to execute arbitrary SQL commands via the cat parameter, a different vector than CVE-2008-4880.
|
CWE-89
SQL Injection
|
CVE-2008-4879
|
2017-09-29 10:32 |
2008-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292177
|
- |
|
maran
|
php_shop
|
SQL injection vulnerability in prodshow.php in Maran PHP Shop allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2008-4879.
|
CWE-89
SQL Injection
|
CVE-2008-4880
|
2017-09-29 10:32 |
2008-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292178
|
- |
|
yourfreeworld
|
reminder_service_script
|
SQL injection vulnerability in tr.php in YourFreeWorld Reminder Service Script allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2008-4881
|
2017-09-29 10:32 |
2008-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292179
|
- |
|
yourfreeworld
|
autoresponder_hosting_script
|
SQL injection vulnerability in tr.php in YourFreeWorld Autoresponder Hosting Script allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2008-4882
|
2017-09-29 10:32 |
2008-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292180
|
- |
|
yourfreeworld
|
blog_blaster_script
|
SQL injection vulnerability in tr.php in YourFreeWorld Blog Blaster Script allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2008-4883
|
2017-09-29 10:32 |
2008-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|