270781
|
- |
|
tftpd32
|
tftpd32
|
tftpd32 2.50 and 2.50.2 allows remote attackers to read or write arbitrary files via a full pathname in GET and PUT requests.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2002-2353
|
2009-11-24 14:15 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270782
|
- |
|
betsy
|
betsy_cms
|
Directory traversal vulnerability in admin/popup.php in Betsy CMS 3.5 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the popup parameter.
|
CWE-22
Path Traversal
|
CVE-2009-4056
|
2009-11-24 14:00 |
2009-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270783
|
- |
|
p-hd
|
phd_help_desk
|
Multiple cross-site scripting (XSS) vulnerabilities in PHD Help Desk 1.43 allow remote attackers to inject arbitrary web script or HTML via (1) the PATH_INFO to area.php; the (2) pagina, (3) sentido,…
|
CWE-79
Cross-site Scripting
|
CVE-2009-4047
|
2009-11-24 02:30 |
2009-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270784
|
- |
|
phpmybackuppro
|
phpmybackuppro
|
Directory traversal vulnerability in get_file.php in phpMyBackupPro 2.1 allows remote attackers to read arbitrary files via directory traversal sequences in the view parameter. NOTE: the provenance …
|
CWE-22
Path Traversal
|
CVE-2009-4050
|
2009-11-24 02:30 |
2009-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270785
|
- |
|
frontaccounting
|
frontaccounting
|
Multiple SQL injection vulnerabilities in FrontAccounting (FA) before 2.1.7, and 2.2.x before 2.2 RC, allow remote attackers to execute arbitrary SQL commands via unspecified parameters to (1) admin/…
|
CWE-89
SQL Injection
|
CVE-2009-4037
|
2009-11-23 14:00 |
2009-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270786
|
- |
|
nch
|
axon_virtual_pbx
|
Multiple cross-site scripting (XSS) vulnerabilities in NCH Software Axon Virtual PBX 2.10 and 2.11 allow remote attackers to inject arbitrary web script or HTML via the (1) onok or (2) oncancel param…
|
CWE-79
Cross-site Scripting
|
CVE-2009-4038
|
2009-11-23 14:00 |
2009-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270787
|
- |
|
piwigo
|
piwigo
|
Cross-site scripting (XSS) vulnerability in Piwigo before 2.0.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2009-4039
|
2009-11-23 14:00 |
2009-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270788
|
- |
|
usebb
|
usebb
|
UseBB 1.0.9 before 1.0.10 allows remote attackers to cause a denial of service (infinite loop) via crafted BBCode tags.
|
NVD-CWE-Other
|
CVE-2009-4041
|
2009-11-23 14:00 |
2009-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270789
|
- |
|
frontaccounting
|
frontaccounting
|
Multiple SQL injection vulnerabilities in FrontAccounting (FA) before 2.1.7 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to various .inc and .php files in (1) r…
|
CWE-89
SQL Injection
|
CVE-2009-4045
|
2009-11-23 14:00 |
2009-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270790
|
- |
|
frontaccounting
|
frontaccounting
|
Multiple SQL injection vulnerabilities in FrontAccounting (FA) 2.2.x before 2.2 RC allow remote attackers to execute arbitrary SQL commands via unspecified parameters to (1) bank_accounts.php, (2) cu…
|
CWE-89
SQL Injection
|
CVE-2009-4046
|
2009-11-23 14:00 |
2009-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|