Логотип exploitDog
source:"nvd"
Консоль
Логотип exploitDog

exploitDog

source:"nvd"

Количество 332 146

Количество 332 146

nvd логотип

CVE-2008-5586

около 17 лет назад

SQL injection vulnerability in findoffice.php in Check Up New Generation (aka Check New) 4.52, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the search parameter.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2008-5585

около 17 лет назад

Multiple PHP remote file inclusion vulnerabilities in lcxBBportal 0.1 Alpha 2 allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter to (1) portal/includes/portal_block.php and (2) includes/acp/acp_lcxbbportal.php.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2008-5584

около 17 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in ProjectPier 0.8 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) a message, (2) a milestone, or (3) a display name in a profile, or the (4) a or (5) c parameter to index.php.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2008-5583

около 17 лет назад

Cross-site request forgery (CSRF) vulnerability in index.php in ProjectPier 0.8 and earlier allows remote attackers to perform actions as an administrator via the query string, as demonstrated by a delete project action.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2008-5582

около 17 лет назад

SQL injection vulnerability in utilities/login.asp in Nukedit 4.9.x, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the email parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2008-5581

около 17 лет назад

PHP remote file inclusion vulnerability in mini-pub.php/front-end/img.php in mini-pub 0.3 allows remote attackers to execute arbitrary PHP code via a URL in the sFileName parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2008-5580

около 17 лет назад

mini-pub.php/front-end/cat.php in mini-pub 0.3 allows remote attackers to execute arbitrary commands via shell metacharacters in the sFileName argument.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2008-5579

около 17 лет назад

Absolute path traversal vulnerability in mini-pub.php/front-end/cat.php in mini-pub 0.3 allows remote attackers to read arbitrary files via a full pathname in the sFileName parameter.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2008-5578

около 17 лет назад

Multiple SQL injection vulnerabilities in index.php in sCssBoard 1.0, 1.1, 1.11, and 1.12 allow remote attackers to execute arbitrary SQL commands via (1) the f parameter in a showforum action, (2) the u parameter in a profile action, (3) the viewcat parameter, or (4) a combination of scb_uid and scb_ident cookie values.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2008-5577

около 17 лет назад

PHP remote file inclusion vulnerability in index.php in sCssBoard 1.0, 1.1, 1.11, and 1.12 allows remote attackers to execute arbitrary PHP code via a URL in the inc_function parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2008-5576

около 17 лет назад

admin/forums.php in sCssBoard 1.0, 1.1, 1.11, and 1.12 allows remote attackers to bypass authentication and gain administrative access via a large value of the current_user[users_level] parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2008-5575

около 17 лет назад

Session fixation vulnerability in Pro Clan Manager 0.4.2 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2008-5574

около 17 лет назад

SQL injection vulnerability in member.php in Webmaster Marketplace allows remote attackers to execute arbitrary SQL commands via the u parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2008-5573

около 17 лет назад

SQL injection vulnerability in the login feature in Poll Pro 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) Password and (2) username parameters.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2008-5572

около 17 лет назад

Professional Download Assistant 0.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for database/downloads.mdb.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2008-5571

около 17 лет назад

SQL injection vulnerability in admin/login.asp in Professional Download Assistant 0.1 allows remote attackers to execute arbitrary SQL commands via the (1) uname parameter (aka user field) or the (2) psw parameter (aka passwd field). NOTE: some of these details are obtained from third party information.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2008-5570

около 17 лет назад

Directory traversal vulnerability in index.php in PHP Multiple Newsletters 2.7, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2008-5569

около 17 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in PHPepperShop 1.4 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) index.php or (2) shop/kontakt.php, or (3) shop_kunden_mgmt.php or (4) SHOP_KONFIGURATION.php in shop/Admin/.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2008-5568

около 17 лет назад

Cross-site request forgery (CSRF) vulnerability in admin/settings.php in IPN Pro 3 1.44 and earlier allows remote attackers to change the admin password via a logout action in conjunction with the admin_id, newpass_1, and newpass_2 parameters.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2008-5567

около 17 лет назад

Cross-site request forgery (CSRF) vulnerability in admin/ad_settings.php in Bonza Cart 1.10 and earlier allows remote attackers to change the admin password via a logout action in conjunction with the NewAdmin, NewPass1, and NewPass2 parameters.

CVSS2: 6.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2008-5586

SQL injection vulnerability in findoffice.php in Check Up New Generation (aka Check New) 4.52, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the search parameter.

CVSS2: 6.8
0%
Низкий
около 17 лет назад
nvd логотип
CVE-2008-5585

Multiple PHP remote file inclusion vulnerabilities in lcxBBportal 0.1 Alpha 2 allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter to (1) portal/includes/portal_block.php and (2) includes/acp/acp_lcxbbportal.php.

CVSS2: 7.5
4%
Низкий
около 17 лет назад
nvd логотип
CVE-2008-5584

Multiple cross-site scripting (XSS) vulnerabilities in ProjectPier 0.8 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) a message, (2) a milestone, or (3) a display name in a profile, or the (4) a or (5) c parameter to index.php.

CVSS2: 4.3
3%
Низкий
около 17 лет назад
nvd логотип
CVE-2008-5583

Cross-site request forgery (CSRF) vulnerability in index.php in ProjectPier 0.8 and earlier allows remote attackers to perform actions as an administrator via the query string, as demonstrated by a delete project action.

CVSS2: 6.8
0%
Низкий
около 17 лет назад
nvd логотип
CVE-2008-5582

SQL injection vulnerability in utilities/login.asp in Nukedit 4.9.x, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the email parameter.

CVSS2: 7.5
0%
Низкий
около 17 лет назад
nvd логотип
CVE-2008-5581

PHP remote file inclusion vulnerability in mini-pub.php/front-end/img.php in mini-pub 0.3 allows remote attackers to execute arbitrary PHP code via a URL in the sFileName parameter.

CVSS2: 7.5
3%
Низкий
около 17 лет назад
nvd логотип
CVE-2008-5580

mini-pub.php/front-end/cat.php in mini-pub 0.3 allows remote attackers to execute arbitrary commands via shell metacharacters in the sFileName argument.

CVSS2: 7.5
4%
Низкий
около 17 лет назад
nvd логотип
CVE-2008-5579

Absolute path traversal vulnerability in mini-pub.php/front-end/cat.php in mini-pub 0.3 allows remote attackers to read arbitrary files via a full pathname in the sFileName parameter.

CVSS2: 5
4%
Низкий
около 17 лет назад
nvd логотип
CVE-2008-5578

Multiple SQL injection vulnerabilities in index.php in sCssBoard 1.0, 1.1, 1.11, and 1.12 allow remote attackers to execute arbitrary SQL commands via (1) the f parameter in a showforum action, (2) the u parameter in a profile action, (3) the viewcat parameter, or (4) a combination of scb_uid and scb_ident cookie values.

CVSS2: 7.5
0%
Низкий
около 17 лет назад
nvd логотип
CVE-2008-5577

PHP remote file inclusion vulnerability in index.php in sCssBoard 1.0, 1.1, 1.11, and 1.12 allows remote attackers to execute arbitrary PHP code via a URL in the inc_function parameter.

CVSS2: 7.5
3%
Низкий
около 17 лет назад
nvd логотип
CVE-2008-5576

admin/forums.php in sCssBoard 1.0, 1.1, 1.11, and 1.12 allows remote attackers to bypass authentication and gain administrative access via a large value of the current_user[users_level] parameter.

CVSS2: 7.5
2%
Низкий
около 17 лет назад
nvd логотип
CVE-2008-5575

Session fixation vulnerability in Pro Clan Manager 0.4.2 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.

CVSS2: 7.5
0%
Низкий
около 17 лет назад
nvd логотип
CVE-2008-5574

SQL injection vulnerability in member.php in Webmaster Marketplace allows remote attackers to execute arbitrary SQL commands via the u parameter.

CVSS2: 7.5
1%
Низкий
около 17 лет назад
nvd логотип
CVE-2008-5573

SQL injection vulnerability in the login feature in Poll Pro 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) Password and (2) username parameters.

CVSS2: 7.5
1%
Низкий
около 17 лет назад
nvd логотип
CVE-2008-5572

Professional Download Assistant 0.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for database/downloads.mdb.

CVSS2: 5
5%
Низкий
около 17 лет назад
nvd логотип
CVE-2008-5571

SQL injection vulnerability in admin/login.asp in Professional Download Assistant 0.1 allows remote attackers to execute arbitrary SQL commands via the (1) uname parameter (aka user field) or the (2) psw parameter (aka passwd field). NOTE: some of these details are obtained from third party information.

CVSS2: 7.5
1%
Низкий
около 17 лет назад
nvd логотип
CVE-2008-5570

Directory traversal vulnerability in index.php in PHP Multiple Newsletters 2.7, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter.

CVSS2: 6.8
7%
Низкий
около 17 лет назад
nvd логотип
CVE-2008-5569

Multiple cross-site scripting (XSS) vulnerabilities in PHPepperShop 1.4 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) index.php or (2) shop/kontakt.php, or (3) shop_kunden_mgmt.php or (4) SHOP_KONFIGURATION.php in shop/Admin/.

CVSS2: 4.3
2%
Низкий
около 17 лет назад
nvd логотип
CVE-2008-5568

Cross-site request forgery (CSRF) vulnerability in admin/settings.php in IPN Pro 3 1.44 and earlier allows remote attackers to change the admin password via a logout action in conjunction with the admin_id, newpass_1, and newpass_2 parameters.

CVSS2: 6.8
0%
Низкий
около 17 лет назад
nvd логотип
CVE-2008-5567

Cross-site request forgery (CSRF) vulnerability in admin/ad_settings.php in Bonza Cart 1.10 and earlier allows remote attackers to change the admin password via a logout action in conjunction with the NewAdmin, NewPass1, and NewPass2 parameters.

CVSS2: 6.8
0%
Низкий
около 17 лет назад

Уязвимостей на страницу