271211
|
- |
|
vastal
|
agent_zone
|
SQL injection vulnerability in view_listing.php in Vastal I-Tech Agent Zone (aka The Real Estate Script) allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2009-3497
|
2009-10-1 13:00 |
2009-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
271212
|
- |
|
hbcms
|
hbcms
|
SQL injection vulnerability in php/update_article_hits.php in HBcms 1.7 allows remote attackers to execute arbitrary SQL commands via the article_id parameter.
|
CWE-89
SQL Injection
|
CVE-2009-3498
|
2009-10-1 13:00 |
2009-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
271213
|
- |
|
bpowerhouse
|
bplawyercasedocuments
|
SQL injection vulnerability in employee.aspx in BPowerHouse BPLawyerCaseDocuments 1.0 allows remote attackers to execute arbitrary SQL commands via the cat parameter.
|
CWE-89
SQL Injection
|
CVE-2009-3499
|
2009-10-1 13:00 |
2009-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
271214
|
- |
|
bpowerhouse
|
bpgames
|
Multiple SQL injection vulnerabilities in BPowerHouse BPGames 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) cat_id parameter to main.php and (2) game_id parameter to game.p…
|
CWE-89
SQL Injection
|
CVE-2009-3500
|
2009-10-1 13:00 |
2009-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
271215
|
- |
|
bpowerhouse
|
bpmusic
|
SQL injection vulnerability in music.php in BPowerHouse BPMusic 1.0 allows remote attackers to execute arbitrary SQL commands via the music_id parameter.
|
CWE-89
SQL Injection
|
CVE-2009-3502
|
2009-10-1 13:00 |
2009-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
271216
|
- |
|
bpowerhouse
|
bpholidaylettings
|
Multiple SQL injection vulnerabilities in search.aspx in BPowerHouse BPHolidayLettings 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) rid and (2) tid parameters.
|
CWE-89
SQL Injection
|
CVE-2009-3503
|
2009-10-1 13:00 |
2009-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
271217
|
- |
|
alibabaclone
|
alibaba_clone
|
SQL injection vulnerability in offers_buy.php in Alibaba Clone 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2009-3504
|
2009-10-1 13:00 |
2009-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
271218
|
- |
|
henriksjokvist
|
markdown_preview
|
Cross-site scripting (XSS) vulnerability in the live preview feature in the Markdown Preview module 6.x for Drupal allows remote attackers to inject arbitrary web script or HTML via "Markdown input."
|
CWE-79
Cross-site Scripting
|
CVE-2009-3437
|
2009-09-30 13:00 |
2009-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
271219
|
- |
|
apple
|
safari
|
Apple Safari, possibly before 4.0.3, on Mac OS X does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-mi…
|
CWE-310
Cryptographic Issues
|
CVE-2009-3455
|
2009-09-30 13:00 |
2009-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
271220
|
- |
|
google
|
chrome
|
Google Chrome, possibly 3.0.195.21 and earlier, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-mid…
|
CWE-310
Cryptographic Issues
|
CVE-2009-3456
|
2009-09-30 13:00 |
2009-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|