Show filters
530 Total Results
Displaying 421-430 of 530
Sort by:
Attacker Value
Unknown
CVE-2008-5763
Disclosure Date: December 30, 2008 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in slogin_lib.inc.php in Simple Text-File Login Script (SiTeFiLo) 1.0.6 allows remote attackers to execute arbitrary PHP code via a URL in the slogin_path parameter.
0
Attacker Value
Unknown
CVE-2008-5270
Disclosure Date: November 28, 2008 (last updated October 04, 2023)
SQL injection vulnerability in view.topics.php in Yuhhu Superstar 2008 allows remote attackers to execute arbitrary SQL commands via the board parameter.
0
Attacker Value
Unknown
CVE-2008-5218
Disclosure Date: November 25, 2008 (last updated October 04, 2023)
ScriptsEz FREEze Greetings 1.0 stores pwd.txt under the web root with insufficient access control, which allows remote attackers to obtain cleartext passwords.
0
Attacker Value
Unknown
CVE-2008-5136
Disclosure Date: November 18, 2008 (last updated October 04, 2023)
tkusr in tkusr 0.82 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/tkusr.pgm temporary file.
0
Attacker Value
Unknown
CVE-2008-5139
Disclosure Date: November 18, 2008 (last updated October 04, 2023)
updatejail in jailer 0.4 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/#####.updatejail temporary file.
0
Attacker Value
Unknown
CVE-2008-4167
Disclosure Date: September 22, 2008 (last updated October 04, 2023)
useradmin.php in Easy Photo Gallery (aka Ezphotogallery) 2.1 does not require administrative authentication, which allows remote attackers to (1) add or (2) remove an Administrator account.
0
Attacker Value
Unknown
CVE-2008-3943
Disclosure Date: September 05, 2008 (last updated October 04, 2023)
SQL injection vulnerability in listtest.php in eZoneScripts Living Local 1.1 allows remote attackers to execute arbitrary SQL commands via the r parameter.
0
Attacker Value
Unknown
CVE-2008-3575
Disclosure Date: August 10, 2008 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in modules/calendar/minicalendar.php in ezContents CMS allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[gsLanguage] parameter, a different vector than CVE-2006-4477 and CVE-2004-0132.
0
Attacker Value
Unknown
CVE-2008-3292
Disclosure Date: July 24, 2008 (last updated October 04, 2023)
constants.inc in EZWebAlbum 1.0 allows remote attackers to bypass authentication and gain administrator privileges by setting the photoalbumadmin cookie, as demonstrated via addpage.php.
0
Attacker Value
Unknown
CVE-2008-3293
Disclosure Date: July 24, 2008 (last updated October 04, 2023)
Directory traversal vulnerability in download.php in EZWebAlbum allows remote attackers to read arbitrary files via the dlfilename parameter.
0