Show filters
530 Total Results
Displaying 411-420 of 530
Sort by:
Attacker Value
Unknown

CVE-2008-6112

Disclosure Date: February 11, 2009 (last updated October 04, 2023)
Multiple directory traversal vulnerabilities in Ez Ringtone Manager allow remote attackers to read arbitrary files via a .. (dot dot) in the id parameter in a detail action to (1) main.php and (2) template.php in ringtones/.
0
Attacker Value
Unknown

CVE-2008-6101

Disclosure Date: February 10, 2009 (last updated October 04, 2023)
SQL injection vulnerability in click.php in Adult Banner Exchange Website allows remote attackers to execute arbitrary SQL commands via the targetid parameter.
0
Attacker Value
Unknown

CVE-2008-6102

Disclosure Date: February 10, 2009 (last updated October 04, 2023)
SQL injection vulnerability in ratelink.php in Link Trader Script allows remote attackers to execute arbitrary SQL commands via the lnkid parameter.
0
Attacker Value
Unknown

CVE-2008-6090

Disclosure Date: February 06, 2009 (last updated October 04, 2023)
Directory traversal vulnerability in members.php in ScriptsEz Mini Hosting Panel allows remote attackers to read arbitrary local files via a .. (dot dot) in the dir parameter in a view action.
0
Attacker Value
Unknown

CVE-2008-6089

Disclosure Date: February 06, 2009 (last updated October 04, 2023)
Directory traversal vulnerability in main.php in ScriptsEz Easy Image Downloader allows remote attackers to read arbitrary files via a .. (dot dot) in the id parameter in a download action.
0
Attacker Value
Unknown

CVE-2009-0389

Disclosure Date: February 02, 2009 (last updated October 04, 2023)
Multiple insecure method vulnerabilities in the Web On Windows (WOW) ActiveX control in WOW ActiveX 2 allow remote attackers to (1) create and overwrite arbitrary files via the WriteIniFileString method, (2) execute arbitrary programs via the ShellExecute method, (3) read from the registry via unspecified vectors, and (4) write to the registry via unspecified vectors. NOTE: vectors 1 and 2 can be used together to execute arbitrary code.
0
Attacker Value
Unknown

CVE-2009-0275

Disclosure Date: January 26, 2009 (last updated October 04, 2023)
Static code injection vulnerability in admin.php in Ryneezy phoSheezy 0.2 allows remote authenticated administrators to inject arbitrary PHP code into config/header via the header parameter. NOTE: this can be exploited by unauthenticated attackers by leveraging CVE-2009-0250. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown

CVE-2009-0251

Disclosure Date: January 22, 2009 (last updated October 04, 2023)
Static code injection vulnerability in admin.php in Ryneezy phoSheezy 0.2 allows remote authenticated administrators to inject arbitrary PHP code into config/footer via the footer parameter. NOTE: this can be exploited by unauthenticated attackers by leveraging CVE-2009-0250. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2009-0250

Disclosure Date: January 22, 2009 (last updated October 04, 2023)
Ryneezy phoSheezy 0.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the file containing the administrator's password hash via a direct request for config/password.
0
Attacker Value
Unknown

CVE-2008-5762

Disclosure Date: December 30, 2008 (last updated October 04, 2023)
Simple Text-File Login Script (SiTeFiLo) 1.0.6 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing the password via a direct request for slog_users.txt.
0