265201
|
- |
|
devonit
|
thin-client_management_tool
|
The DevonIT thin-client management tool relies on a shared secret for authentication but transmits the secret in cleartext, which makes it easier for remote attackers to discover the secret value, an…
|
CWE-255
Credentials Management
|
CVE-2010-3122
|
2010-08-26 13:00 |
2010-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265202
|
- |
|
smartertools
|
smartertrack
|
Cross-site scripting (XSS) vulnerability in frmKBSearch.aspx in SmarterTools SmarterTrack before 4.0.3504 allows remote attackers to inject arbitrary web script or HTML via the search parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2009-4994
|
2010-08-26 13:00 |
2010-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265203
|
- |
|
smartertools
|
smartertrack
|
Cross-site scripting (XSS) vulnerability in frmTickets.aspx in SmarterTools SmarterTrack before 4.0.3504 allows remote attackers to inject arbitrary web script or HTML via the email address field. N…
|
CWE-79
Cross-site Scripting
|
CVE-2009-4995
|
2010-08-26 13:00 |
2010-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265204
|
- |
|
keil-software
|
photokorn_gallery
|
Multiple SQL injection vulnerabilities in search.php in Photokorn Gallery 1.81 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) where[], (2) sort, (3) order, and (4) M…
|
CWE-89
SQL Injection
|
CVE-2009-4979
|
2010-08-26 05:00 |
2010-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265205
|
- |
|
keil-software
|
photokorn_gallery
|
Multiple cross-site scripting (XSS) vulnerabilities in Photokorn Gallery 1.81 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) where[] parameter to search.php and…
|
CWE-79
Cross-site Scripting
|
CVE-2009-4980
|
2010-08-26 05:00 |
2010-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265206
|
- |
|
keil-software
|
photokorn_gallery
|
Multiple cross-site request forgery (CSRF) vulnerabilities in Photokorn Gallery 1.81 allow remote attackers to hijack the authentication of administrators.
|
CWE-352
Origin Validation Error
|
CVE-2009-4981
|
2010-08-26 05:00 |
2010-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265207
|
- |
|
snowhall
|
silurus_system
|
Multiple cross-site scripting (XSS) vulnerabilities in Silurus Classifieds 1.0 allow remote attackers to inject arbitrary web script or HTML via the ID parameter to (1) category.php and (2) wcategory…
|
CWE-79
Cross-site Scripting
|
CVE-2009-4983
|
2010-08-26 05:00 |
2010-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265208
|
- |
|
ajsquare
|
aj_auction_pro-oopd
|
Cross-site scripting (XSS) vulnerability in index.php in AJ Auction Pro OOPD 3.0 allows remote attackers to inject arbitrary web script or HTML via the txtkeyword parameter in a search action.
|
CWE-79
Cross-site Scripting
|
CVE-2009-4989
|
2010-08-26 05:00 |
2010-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265209
|
- |
|
jrbcs
|
webform_report
|
Cross-site scripting (XSS) vulnerability in the Webform report module 5.x and 6.x for Drupal allows remote attackers to inject arbitrary web script or HTML via a submission.
|
CWE-79
Cross-site Scripting
|
CVE-2009-4990
|
2010-08-26 05:00 |
2010-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265210
|
- |
|
omnistaretools
|
omnistar_recruiting
|
Cross-site scripting (XSS) vulnerability in users/resume_register.php in Omnistar Recruiting allows remote attackers to inject arbitrary web script or HTML via the job2 parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2009-4991
|
2010-08-26 05:00 |
2010-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|