Show filters
321 Total Results
Displaying 261-270 of 321
Sort by:
Attacker Value
Unknown
CVE-2008-5581
Disclosure Date: December 15, 2008 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in mini-pub.php/front-end/img.php in mini-pub 0.3 allows remote attackers to execute arbitrary PHP code via a URL in the sFileName parameter.
0
Attacker Value
Unknown
CVE-2008-3393
Disclosure Date: July 31, 2008 (last updated October 04, 2023)
SQL injection vulnerability in events.cfm in BookMine allows remote attackers to execute arbitrary SQL commands via the events_id parameter.
0
Attacker Value
Unknown
CVE-2008-3390
Disclosure Date: July 31, 2008 (last updated October 04, 2023)
Directory traversal vulnerability in libraries/general.init.php in Minishowcase Image Gallery 09b136, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter.
0
Attacker Value
Unknown
CVE-2008-3394
Disclosure Date: July 31, 2008 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in search.cfm in BookMine allow remote attackers to inject arbitrary web script or HTML via the (1) gallery and (2) search_string parameters.
0
Attacker Value
Unknown
CVE-2008-2961
Disclosure Date: July 02, 2008 (last updated October 04, 2023)
Multiple directory traversal vulnerabilities in view/index.php in CMS Mini 0.2.2 allow remote attackers to read arbitrary local files via a .. (dot dot) in the (1) path and (2) p parameter.
0
Attacker Value
Unknown
CVE-2008-2197
Disclosure Date: May 14, 2008 (last updated October 04, 2023)
SQL injection vulnerability in the blogwriter module 2.0 for Miniweb allows remote attackers to execute arbitrary SQL commands via the historymonth parameter to index.php.
0
Attacker Value
Unknown
CVE-2008-2066
Disclosure Date: May 02, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in bb_admin.php in miniBB 2.2a allows remote attackers to inject arbitrary web script or HTML via the whatus parameter in a searchusers2 action. NOTE: it was later reported that other versions before 3.0.1 are also vulnerable.
0
Attacker Value
Unknown
CVE-2008-2067
Disclosure Date: May 02, 2008 (last updated October 04, 2023)
SQL injection vulnerability in bb_admin.php in miniBB 2.2a allows remote attackers to execute arbitrary SQL commands via the whatus parameter in a searchusers2 action. NOTE: it was later reported that other versions before 3.0.1 are also vulnerable.
0
Attacker Value
Unknown
CVE-2008-2029
Disclosure Date: April 30, 2008 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in (1) setup_mysql.php and (2) setup_options.php in miniBB 2.2 and possibly earlier, when register_globals is enabled, allow remote attackers to execute arbitrary SQL commands via the xtr parameter in a userinfo action to index.php.
0
Attacker Value
Unknown
CVE-2008-2028
Disclosure Date: April 30, 2008 (last updated October 04, 2023)
miniBB 2.2, and possibly earlier, when register_globals is enabled, allows remote attackers to obtain the full path via a direct request to the glang parameter in a registernew action to index.php, which leaks the path in an error message.
0