270921
|
- |
|
richard_ellerbrock
|
ipplan
|
Cross-site scripting (XSS) vulnerability in admin/usermanager in IPplan 4.91a allows remote attackers to inject arbitrary web script or HTML via the grp parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2009-1732
|
2009-07-10 14:33 |
2009-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270922
|
- |
|
eggheads
|
eggdrop_irc_bot
|
Stack-based buffer overflow in mod/server.mod/servrmsg.c in Eggdrop 1.6.18, and possibly earlier, allows user-assisted, remote IRC servers to execute arbitrary code via a long private message.
|
NVD-CWE-Other
|
CVE-2007-2807
|
2009-07-10 14:05 |
2007-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270923
|
- |
|
zoph
|
zoph
|
Cross-site scripting (XSS) vulnerability in people.php in Zoph before 0.7.0.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: some of these details are …
|
CWE-79
Cross-site Scripting
|
CVE-2009-2343
|
2009-07-9 13:00 |
2009-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270924
|
- |
|
ebay
|
enhanced_picture_uploader_activex_control
|
eBay Enhanced Picture Uploader ActiveX control (EPUWALcontrol.dll) before 1.0.27 allows remote attackers to execute arbitrary commands via the PictureUrls property.
|
CWE-78
OS Command
|
CVE-2008-2475
|
2009-07-9 13:00 |
2009-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270925
|
- |
|
ebay
|
enhanced_picture_uploader_activex_control
|
Per http://www.kb.cert.org/vuls/id/983731
This update is addressed in version 1.0.27 of the Ebay Enhanced Picture Control software.
|
CWE-78
OS Command
|
CVE-2008-2475
|
2009-07-9 13:00 |
2009-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270926
|
- |
|
matteo_ricchetti
|
ss5
|
Unspecified vulnerability in Socks Server 5 before 3.7.8-8 has unknown impact and attack vectors.
|
NVD-CWE-noinfo
|
CVE-2009-2368
|
2009-07-9 00:30 |
2009-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270927
|
- |
|
michelle_cox
|
advanced_forum
|
Cross-site scripting (XSS) vulnerability in Advanced Forum 5.x before 5.x-1.1 and 6.x before 6.x-1.1, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecifi…
|
CWE-79
Cross-site Scripting
|
CVE-2009-2370
|
2009-07-9 00:30 |
2009-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270928
|
- |
|
michelle_cox
|
advanced_forum
|
Advanced Forum 6.x before 6.x-1.1, a module for Drupal, does not prevent users from modifying user signatures after the associated comment format has been changed to an administrator-controlled input…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-2371
|
2009-07-9 00:30 |
2009-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270929
|
- |
|
drupal
|
drupal
|
Cross-site scripting (XSS) vulnerability in the Forum module in Drupal 6.x before 6.13 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2009-2373
|
2009-07-9 00:30 |
2009-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270930
|
- |
|
hans_oesterholt
|
cmme
|
Cross-site scripting (XSS) vulnerability in admin.php (aka the login page) in Content Management Made Easy (CMME) before 1.22 allows remote attackers to inject arbitrary web script or HTML via the us…
|
CWE-79
Cross-site Scripting
|
CVE-2009-2342
|
2009-07-8 13:00 |
2009-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|