|
292731
|
- |
|
ultrastats
|
ultrastats
|
SQL injection vulnerability in index.php in Ultrastats 0.2.144 and 0.3.11 allows remote attackers to execute arbitrary SQL commands via the serverid parameter.
|
CWE-89
SQL Injection
|
CVE-2008-6260
|
2017-09-29 10:33 |
2009-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292732
|
- |
|
e-topbiz
|
admanager
|
SQL injection vulnerability in view.php in E-topbiz AdManager 4 allows remote attackers to execute arbitrary SQL commands via the group parameter.
|
CWE-89
SQL Injection
|
CVE-2008-6261
|
2017-09-29 10:33 |
2009-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292733
|
- |
|
infireal
|
saturncms
|
SQL injection vulnerability in lib/user/t_user.php in SaturnCMS allows remote attackers to execute arbitrary SQL commands via the username parameter to the _userLoggedIn function. NOTE: some of thes…
|
CWE-89
SQL Injection
|
CVE-2008-6263
|
2017-09-29 10:33 |
2009-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292734
|
- |
|
e-topbiz
|
slide_popups
|
SQL injection vulnerability in admin/admin.php in E-topbiz Slide Popups 1.0 allows remote attackers to execute arbitrary SQL commands via the password parameter.
|
CWE-89
SQL Injection
|
CVE-2008-6264
|
2017-09-29 10:33 |
2009-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292735
|
- |
|
cyberfolio
|
cyberfolio
|
Directory traversal vulnerability in portfolio/css.php in Cyberfolio 7.12.2 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the theme parameter.
|
CWE-22
Path Traversal
|
CVE-2008-6265
|
2017-09-29 10:33 |
2009-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292736
|
- |
|
sadi_samami
|
multi_languages_webshop_online
|
Cross-site scripting (XSS) vulnerability in detail.php in Multi Languages WebShop Online 1.02 allows remote attackers to inject arbitrary web script or HTML via the name parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2008-6267
|
2017-09-29 10:33 |
2009-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292737
|
- |
|
sadi_samami
|
multi_languages_webshop_online
|
SQL injection vulnerability in detail.php in WEBBDOMAIN Multi Languages WebShop Online 1.02 allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2008-6268
|
2017-09-29 10:33 |
2009-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292738
|
- |
|
joovili
|
joovili
|
Joovili 3.1.4 allows remote attackers to bypass authentication and gain privileges as other users, including the administrator, by setting the (1) session_id, session_logged_in, and session_username …
|
CWE-287
Improper Authentication
|
CVE-2008-6269
|
2017-09-29 10:33 |
2009-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292739
|
- |
|
miticdjd
|
apoll
|
SQL injection vulnerability in admin/index.php in Dragan Mitic Apoll 0.7 beta and 0.7.5 allows remote attackers to execute arbitrary SQL command via the user parameter.
|
CWE-89
SQL Injection
|
CVE-2008-6270
|
2017-09-29 10:33 |
2009-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292740
|
- |
|
tbmnet
|
tbmnetcms
|
Directory traversal vulnerability in index.php in TBmnetCMS 1.0, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the content parameter.
|
CWE-22
Path Traversal
|
CVE-2008-6271
|
2017-09-29 10:33 |
2009-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|