268001
|
- |
|
freenas
|
freenas
|
Cross-site request forgery (CSRF) vulnerability in the WebGUI in FreeNAS before 0.7RC1 allows remote attackers to hijack the authentication of users for unspecified requests via unknown vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2009-2738
|
2009-08-18 13:00 |
2009-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268002
|
- |
|
ajsquare
|
aj_matrix_dna
|
SQL injection vulnerability in index.php in AJ Matrix DNA allows remote attackers to execute arbitrary SQL commands via the id parameter in a productdetail action.
|
CWE-89
SQL Injection
|
CVE-2009-2779
|
2009-08-18 01:30 |
2009-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268003
|
- |
|
sellatsite.com
|
smart_asp_survey
|
SQL injection vulnerability in showresult.asp in Smart ASP Survey allows remote attackers to execute arbitrary SQL commands via the catid parameter.
|
CWE-89
SQL Injection
|
CVE-2009-2776
|
2009-08-17 13:00 |
2009-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268004
|
- |
|
sun
|
java_system_access_manager java_system_web_server opensso_enterprise
|
Sun Java System Access Manager 6.3 2005Q1, 7.0 2005Q4, and 7.1; and OpenSSO Enterprise 8.0; when AMConfig.properties enables the debug flag, allows local users to discover cleartext passwords by read…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-2712
|
2009-08-15 14:23 |
2009-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268005
|
- |
|
sun
|
java_system_access_manager java_system_web_server
|
The CDCServlet component in Sun Java System Access Manager 7.0 2005Q4 and 7.1, when Cross Domain Single Sign On (CDSSO) is enabled, does not ensure that "policy advice" is presented to the correct cl…
|
NVD-CWE-noinfo
|
CVE-2009-2713
|
2009-08-15 14:23 |
2009-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268006
|
- |
|
freearcadescript
|
free_arcade_script
|
Cross-site scripting (XSS) vulnerability in Free Arcade Script 1.3 allows remote attackers to inject arbitrary web script or HTML via the keyword parameter to the default URI under search/.
|
CWE-79
Cross-site Scripting
|
CVE-2009-2771
|
2009-08-15 02:30 |
2009-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268007
|
- |
|
squid-cache
|
squid
|
Squid 3.0 through 3.0.STABLE16 and 3.1 through 3.1.0.11 does not properly enforce "buffer limits and related bound checks," which allows remote attackers to cause a denial of service via (1) an incom…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-2621
|
2009-08-12 14:30 |
2009-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268008
|
- |
|
squid-cache
|
squid
|
Squid 3.0 through 3.0.STABLE16 and 3.1 through 3.1.0.11 allows remote attackers to cause a denial of service via malformed requests including (1) "missing or mismatched protocol identifier," (2) miss…
|
CWE-20
Improper Input Validation
|
CVE-2009-2622
|
2009-08-12 14:30 |
2009-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268009
|
- |
|
znc
|
znc
|
Directory traversal vulnerability in ZNC before 0.072 allows remote attackers to overwrite arbitrary files via a crafted DCC SEND request.
|
CWE-22
Path Traversal
|
CVE-2009-2658
|
2009-08-12 14:30 |
2009-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268010
|
- |
|
django_project
|
django
|
The Admin media handler in core/servers/basehttp.py in Django 1.0 and 0.96 does not properly map URL requests to expected "static media files," which allows remote attackers to conduct directory trav…
|
CWE-22
Path Traversal
|
CVE-2009-2659
|
2009-08-12 14:30 |
2009-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|