257391
|
- |
|
coolplayer
|
coolplayer
|
Stack-based buffer overflow in PortableApps CoolPlayer Portable (aka CoolPlayer+ Portable) 2.19.1 allows remote attackers to execute arbitrary code via a skin file (skin.ini) with a large PlaylistSki…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-1449
|
2017-09-29 10:34 |
2009-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257392
|
- |
|
bluevirus-design
|
sma-db
|
PHP remote file inclusion vulnerability in format.php in SMA-DB 0.3.12 allows remote attackers to execute arbitrary PHP code via a URL in the _page_content parameter.
|
CWE-94
Code Injection
|
CVE-2009-1450
|
2017-09-29 10:34 |
2009-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257393
|
- |
|
bluevirus-design
|
sma-db
|
Cross-site scripting (XSS) vulnerability in startpage.php in SMA-DB 0.3.12 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.
|
CWE-79
Cross-site Scripting
|
CVE-2009-1451
|
2017-09-29 10:34 |
2009-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257394
|
- |
|
bluevirus-design
|
sma-db
|
Multiple PHP remote file inclusion vulnerabilities in theme/format.php in SMA-DB 0.3.13 allow remote attackers to execute arbitrary PHP code via a URL in the (1) _page_css and (2) _page_javascript pa…
|
CWE-94
Code Injection
|
CVE-2009-1452
|
2017-09-29 10:34 |
2009-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257395
|
- |
|
studiolounge
|
address_book
|
Unrestricted file upload vulnerability in upload-file.php in Adam Patterson Studio Lounge Address Book 2.5, as reachable from index2.php, allows remote attackers to execute arbitrary code by uploadin…
|
NVD-CWE-Other
|
CVE-2009-1483
|
2017-09-29 10:34 |
2009-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257396
|
- |
|
ninjadesigns
|
flatchat
|
Directory traversal vulnerability in pmscript.php in Flatchat 3.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the with parameter.
|
CWE-22
Path Traversal
|
CVE-2009-1486
|
2017-09-29 10:34 |
2009-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257397
|
- |
|
rens_rikkerink
|
fungamez
|
SQL injection vulnerability in pages/login.php in FunGamez RC1 allows remote attackers to execute arbitrary SQL commands via the login_user (aka username) parameter. NOTE: some of these details are …
|
CWE-89
SQL Injection
|
CVE-2009-1487
|
2017-09-29 10:34 |
2009-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257398
|
- |
|
rens_rikkerink
|
fungamez
|
Directory traversal vulnerability in admin/load.php in FunGamez RC1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the module parameter to index.php.
|
CWE-22
Path Traversal
|
CVE-2009-1488
|
2017-09-29 10:34 |
2009-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257399
|
- |
|
rens_rikkerink
|
fungamez
|
includes/user.php in Fungamez RC1 allows remote attackers to bypass authentication and gain administrative access by setting the user cookie parameter.
|
CWE-287
Improper Authentication
|
CVE-2009-1489
|
2017-09-29 10:34 |
2009-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257400
|
- |
|
webfileexplorer
|
web_file_explorer
|
Web File Explorer 3.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for data/db.mdb.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-1495
|
2017-09-29 10:34 |
2009-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|