Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 384 790

Количество 384 790

nvd логотип

CVE-2008-6302

больше 17 лет назад

TurnkeyForms Local Classifieds allows remote attackers to bypass authentication and gain administrative access via a direct request to Site_Admin/admin.php.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2008-6301

больше 17 лет назад

SQL injection vulnerability in shoutbox_view.php in the Small ShoutBox module 1.4 for phpBB allows remote attackers to execute arbitrary SQL commands via the id parameter in a delete action.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2008-6300

больше 17 лет назад

Galatolo WebManager 1.3a allows remote attackers to bypass authentication and gain administrative access by setting the (1) gwm_user and (2) gwm_pass cookies to admin. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2008-6299

больше 17 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Joomla! 1.5.7 and earlier allow remote authenticated users with certain privileges to inject arbitrary web script or HTML via (1) the title and description parameters to the com_weblinks module and (2) unspecified vectors in the com_content module related to "article submission."

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2008-6298

больше 17 лет назад

Unspecified vulnerability in sISAPILocation before 1.0.2.2 allows remote attackers to bypass intended access restrictions for character encoding and the cookie secure flag via unknown vectors related to the "HTTP header rewrite function."

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2008-6297

больше 17 лет назад

Cross-site scripting (XSS) vulnerability in order.php in DHCart allows remote attackers to inject arbitrary web script or HTML via the (1) domain and (2) d1 parameters.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2008-6296

больше 17 лет назад

admin.php in Maran PHP Shop allows remote attackers to bypass authentication and gain administrative access by setting the user cookie to "demo."

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2008-6295

больше 17 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Camera Life 2.6.2b8 allow remote attackers to inject arbitrary web script or HTML via the q parameter to (1) search.php and (2) rss.php; the query string after the image name in (3) photos/photo; the path parameter to (4) folder.php; page parameter and REQUEST_URI to (5) login.php; ver parameter to (6) media.php; theme parameter to (7) modules/iconset/iconset-debug.php; and the REQUEST_URI to (8) index.php.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2008-6294

больше 17 лет назад

admin/Index.php in Acc Statistics 1.1 allows remote attackers to bypass authentication and gain administrative access by setting the username_cookie cookie to "admin."

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2008-6293

больше 17 лет назад

admin/Index.php in Acc Real Estate 4.0 allows remote attackers to bypass authentication and gain administrative access by setting the username_cookie to "admin."

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2008-6292

больше 17 лет назад

Acc Autos 4.0 allows remote attackers to bypass authentication and gain administrative access by setting the (1) username_cookie to "admin," (2) right_cookie to "1," and (3) id_cookie to "1."

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2008-6291

больше 17 лет назад

Acc PHP eMail 1.1 allows remote attackers to bypass authentication and gain administrative access by setting the NEWSLETTERLOGIN cookie to "admin".

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2008-6290

больше 17 лет назад

Directory traversal vulnerability in includefile.php in nicLOR Sito, when register_globals is enabled or magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary files via a .. (dot dot) in the page_file parameter.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2008-6289

больше 17 лет назад

SQL injection vulnerability in cityview.php in Tours Manager 1.0 allows remote attackers to execute arbitrary SQL commands via the cityid parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2008-6288

больше 17 лет назад

Directory traversal vulnerability in download.php in Interface Medien ibase 2.03 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter.

CVSS2: 7.8
EPSS: Низкий
nvd логотип

CVE-2008-6287

больше 17 лет назад

Multiple PHP remote file inclusion vulnerabilities in Broadcast Machine 0.1 allow remote attackers to execute arbitrary PHP code via a URL in the baseDir parameter to (1) MySQLController.php, (2) SQLController.php, (3) SetupController.php, (4) VideoController.php, and (5) ViewController.php in controllers/.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2008-6286

больше 17 лет назад

Multiple SQL injection vulnerabilities in SubscriberStart.asp in Active Newsletter 4.3 allow remote attackers to execute arbitrary SQL commands via (1) the email parameter (aka username or E-mail field), or (2) the password parameter (aka password field), to (a) Subscriber.asp or (b) start.asp. NOTE: some of these details are obtained from third party information.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2008-6285

больше 17 лет назад

SQL injection vulnerability in index.php in PHP TV Portal 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the mid parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2008-6284

больше 17 лет назад

SQL injection vulnerability in edit.php in Z1Exchange 1.0 allows remote attackers to execute arbitrary SQL commands via the site parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2008-6283

больше 17 лет назад

Cross-site scripting (XSS) vulnerability in Subtext 2.0 allows remote attackers to inject arbitrary web script or HTML via a comment, related to "the feature which converts URLs to anchor tags."

CVSS2: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2008-6302

TurnkeyForms Local Classifieds allows remote attackers to bypass authentication and gain administrative access via a direct request to Site_Admin/admin.php.

CVSS2: 7.5
3%
Низкий
больше 17 лет назад
nvd логотип
CVE-2008-6301

SQL injection vulnerability in shoutbox_view.php in the Small ShoutBox module 1.4 for phpBB allows remote attackers to execute arbitrary SQL commands via the id parameter in a delete action.

CVSS2: 7.5
1%
Низкий
больше 17 лет назад
nvd логотип
CVE-2008-6300

Galatolo WebManager 1.3a allows remote attackers to bypass authentication and gain administrative access by setting the (1) gwm_user and (2) gwm_pass cookies to admin. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

CVSS2: 7.5
3%
Низкий
больше 17 лет назад
nvd логотип
CVE-2008-6299

Multiple cross-site scripting (XSS) vulnerabilities in Joomla! 1.5.7 and earlier allow remote authenticated users with certain privileges to inject arbitrary web script or HTML via (1) the title and description parameters to the com_weblinks module and (2) unspecified vectors in the com_content module related to "article submission."

CVSS2: 3.5
1%
Низкий
больше 17 лет назад
nvd логотип
CVE-2008-6298

Unspecified vulnerability in sISAPILocation before 1.0.2.2 allows remote attackers to bypass intended access restrictions for character encoding and the cookie secure flag via unknown vectors related to the "HTTP header rewrite function."

CVSS2: 5
1%
Низкий
больше 17 лет назад
nvd логотип
CVE-2008-6297

Cross-site scripting (XSS) vulnerability in order.php in DHCart allows remote attackers to inject arbitrary web script or HTML via the (1) domain and (2) d1 parameters.

CVSS2: 4.3
1%
Низкий
больше 17 лет назад
nvd логотип
CVE-2008-6296

admin.php in Maran PHP Shop allows remote attackers to bypass authentication and gain administrative access by setting the user cookie to "demo."

CVSS2: 7.5
3%
Низкий
больше 17 лет назад
nvd логотип
CVE-2008-6295

Multiple cross-site scripting (XSS) vulnerabilities in Camera Life 2.6.2b8 allow remote attackers to inject arbitrary web script or HTML via the q parameter to (1) search.php and (2) rss.php; the query string after the image name in (3) photos/photo; the path parameter to (4) folder.php; page parameter and REQUEST_URI to (5) login.php; ver parameter to (6) media.php; theme parameter to (7) modules/iconset/iconset-debug.php; and the REQUEST_URI to (8) index.php.

CVSS2: 4.3
1%
Низкий
больше 17 лет назад
nvd логотип
CVE-2008-6294

admin/Index.php in Acc Statistics 1.1 allows remote attackers to bypass authentication and gain administrative access by setting the username_cookie cookie to "admin."

CVSS2: 7.5
3%
Низкий
больше 17 лет назад
nvd логотип
CVE-2008-6293

admin/Index.php in Acc Real Estate 4.0 allows remote attackers to bypass authentication and gain administrative access by setting the username_cookie to "admin."

CVSS2: 7.5
3%
Низкий
больше 17 лет назад
nvd логотип
CVE-2008-6292

Acc Autos 4.0 allows remote attackers to bypass authentication and gain administrative access by setting the (1) username_cookie to "admin," (2) right_cookie to "1," and (3) id_cookie to "1."

CVSS2: 7.5
3%
Низкий
больше 17 лет назад
nvd логотип
CVE-2008-6291

Acc PHP eMail 1.1 allows remote attackers to bypass authentication and gain administrative access by setting the NEWSLETTERLOGIN cookie to "admin".

CVSS2: 7.5
2%
Низкий
больше 17 лет назад
nvd логотип
CVE-2008-6290

Directory traversal vulnerability in includefile.php in nicLOR Sito, when register_globals is enabled or magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary files via a .. (dot dot) in the page_file parameter.

CVSS2: 6.8
2%
Низкий
больше 17 лет назад
nvd логотип
CVE-2008-6289

SQL injection vulnerability in cityview.php in Tours Manager 1.0 allows remote attackers to execute arbitrary SQL commands via the cityid parameter.

CVSS2: 7.5
1%
Низкий
больше 17 лет назад
nvd логотип
CVE-2008-6288

Directory traversal vulnerability in download.php in Interface Medien ibase 2.03 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter.

CVSS2: 7.8
3%
Низкий
больше 17 лет назад
nvd логотип
CVE-2008-6287

Multiple PHP remote file inclusion vulnerabilities in Broadcast Machine 0.1 allow remote attackers to execute arbitrary PHP code via a URL in the baseDir parameter to (1) MySQLController.php, (2) SQLController.php, (3) SetupController.php, (4) VideoController.php, and (5) ViewController.php in controllers/.

CVSS2: 7.5
2%
Низкий
больше 17 лет назад
nvd логотип
CVE-2008-6286

Multiple SQL injection vulnerabilities in SubscriberStart.asp in Active Newsletter 4.3 allow remote attackers to execute arbitrary SQL commands via (1) the email parameter (aka username or E-mail field), or (2) the password parameter (aka password field), to (a) Subscriber.asp or (b) start.asp. NOTE: some of these details are obtained from third party information.

CVSS2: 7.5
1%
Низкий
больше 17 лет назад
nvd логотип
CVE-2008-6285

SQL injection vulnerability in index.php in PHP TV Portal 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the mid parameter.

CVSS2: 7.5
1%
Низкий
больше 17 лет назад
nvd логотип
CVE-2008-6284

SQL injection vulnerability in edit.php in Z1Exchange 1.0 allows remote attackers to execute arbitrary SQL commands via the site parameter.

CVSS2: 7.5
1%
Низкий
больше 17 лет назад
nvd логотип
CVE-2008-6283

Cross-site scripting (XSS) vulnerability in Subtext 2.0 allows remote attackers to inject arbitrary web script or HTML via a comment, related to "the feature which converts URLs to anchor tags."

CVSS2: 4.3
1%
Низкий
больше 17 лет назад

Уязвимостей на страницу