Show filters
321 Total Results
Displaying 261-270 of 321
Sort by:
Attacker Value
Unknown

CVE-2008-5581

Disclosure Date: December 15, 2008 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in mini-pub.php/front-end/img.php in mini-pub 0.3 allows remote attackers to execute arbitrary PHP code via a URL in the sFileName parameter.
0
Attacker Value
Unknown

CVE-2008-3393

Disclosure Date: July 31, 2008 (last updated October 04, 2023)
SQL injection vulnerability in events.cfm in BookMine allows remote attackers to execute arbitrary SQL commands via the events_id parameter.
0
Attacker Value
Unknown

CVE-2008-3390

Disclosure Date: July 31, 2008 (last updated October 04, 2023)
Directory traversal vulnerability in libraries/general.init.php in Minishowcase Image Gallery 09b136, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter.
0
Attacker Value
Unknown

CVE-2008-3394

Disclosure Date: July 31, 2008 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in search.cfm in BookMine allow remote attackers to inject arbitrary web script or HTML via the (1) gallery and (2) search_string parameters.
0
Attacker Value
Unknown

CVE-2008-2961

Disclosure Date: July 02, 2008 (last updated October 04, 2023)
Multiple directory traversal vulnerabilities in view/index.php in CMS Mini 0.2.2 allow remote attackers to read arbitrary local files via a .. (dot dot) in the (1) path and (2) p parameter.
0
Attacker Value
Unknown

CVE-2008-2197

Disclosure Date: May 14, 2008 (last updated October 04, 2023)
SQL injection vulnerability in the blogwriter module 2.0 for Miniweb allows remote attackers to execute arbitrary SQL commands via the historymonth parameter to index.php.
0
Attacker Value
Unknown

CVE-2008-2066

Disclosure Date: May 02, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in bb_admin.php in miniBB 2.2a allows remote attackers to inject arbitrary web script or HTML via the whatus parameter in a searchusers2 action. NOTE: it was later reported that other versions before 3.0.1 are also vulnerable.
0
Attacker Value
Unknown

CVE-2008-2067

Disclosure Date: May 02, 2008 (last updated October 04, 2023)
SQL injection vulnerability in bb_admin.php in miniBB 2.2a allows remote attackers to execute arbitrary SQL commands via the whatus parameter in a searchusers2 action. NOTE: it was later reported that other versions before 3.0.1 are also vulnerable.
0
Attacker Value
Unknown

CVE-2008-2029

Disclosure Date: April 30, 2008 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in (1) setup_mysql.php and (2) setup_options.php in miniBB 2.2 and possibly earlier, when register_globals is enabled, allow remote attackers to execute arbitrary SQL commands via the xtr parameter in a userinfo action to index.php.
0
Attacker Value
Unknown

CVE-2008-2028

Disclosure Date: April 30, 2008 (last updated October 04, 2023)
miniBB 2.2, and possibly earlier, when register_globals is enabled, allows remote attackers to obtain the full path via a direct request to the glang parameter in a registernew action to index.php, which leaks the path in an error message.
0