257811
|
- |
|
mikedeboer
|
com_zoom
|
SQL injection vulnerability in the Mike de Boer zoom (com_zoom) component 2.0 for Mambo allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php.
|
CWE-89
SQL Injection
|
CVE-2009-4474
|
2017-09-19 10:29 |
2009-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257812
|
- |
|
joomlub
|
com_joomlub
|
SQL injection vulnerability in the Joomlub (com_joomlub) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the aid parameter in an auction edit action to index.php.
|
CWE-89
SQL Injection
|
CVE-2009-4475
|
2017-09-19 10:29 |
2009-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257813
|
- |
|
xstate
|
real_estate
|
SQL injection vulnerability in page.html in Xstate Real Estate 1.0 allows remote attackers to execute arbitrary SQL commands via the pid parameter.
|
CWE-89
SQL Injection
|
CVE-2009-4477
|
2017-09-19 10:29 |
2009-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257814
|
- |
|
xstate
|
real_estate
|
Multiple cross-site scripting (XSS) vulnerabilities in Xstate Real Estate 1.0 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) home.html or (2) lands.html.
|
CWE-79
Cross-site Scripting
|
CVE-2009-4478
|
2017-09-19 10:29 |
2009-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257815
|
- |
|
bpowerhouse
|
mini_cms
|
SQL injection vulnerability in page.php in Mini CMS 1.0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2009-4540
|
2017-09-19 10:29 |
2010-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257816
|
- |
|
isolsoft
|
support_center
|
Multiple PHP remote file inclusion vulnerabilities in IsolSoft Support Center 2.5 allow remote attackers to execute arbitrary PHP code via a URL in the lang parameter to (1) newticket.php or (2) remp…
|
CWE-94
Code Injection
|
CVE-2009-4541
|
2017-09-19 10:29 |
2010-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257817
|
- |
|
isolsoft
|
support_center
|
Cross-site scripting (XSS) vulnerability in newticket.php in IsolSoft Support Center 2.5 allows remote attackers to inject arbitrary web script or HTML via the lang parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2009-4542
|
2017-09-19 10:29 |
2010-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257818
|
- |
|
cromosoft
|
facil_helpdesk
|
PHP remote file inclusion vulnerability in index.php in Cromosoft Technologies Facil Helpdesk 2.3 Lite allows remote attackers to execute arbitrary PHP code via a URL in the lng parameter. NOTE: thi…
|
CWE-94
Code Injection
|
CVE-2009-4543
|
2017-09-19 10:29 |
2010-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257819
|
- |
|
cromosoft
|
facil_helpdesk
|
Cross-site scripting (XSS) vulnerability in kbase/kbase.php in Cromosoft Technologies Facil Helpdesk 2.3 Lite allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.
|
CWE-79
Cross-site Scripting
|
CVE-2009-4544
|
2017-09-19 10:29 |
2010-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257820
|
- |
|
logoshows
|
logoshows_bbs
|
Logoshows BBS 2.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for database/globepersonn…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-4545
|
2017-09-19 10:29 |
2010-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|