257401
|
- |
|
propertymaxpro
|
propertymax_pro_free
|
Cross-site scripting (XSS) vulnerability in index.php in PropertyMax Pro FREE 0.3 allows remote attackers to inject arbitrary web script or HTML via the pl parameter in a mi action.
|
CWE-79
Cross-site Scripting
|
CVE-2009-1951
|
2017-09-29 10:34 |
2009-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257402
|
- |
|
propertymaxpro
|
propertymax_pro_free
|
Multiple SQL injection vulnerabilities in the administrative login feature in PropertyMax Pro FREE 0.3, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via…
|
CWE-89
SQL Injection
|
CVE-2009-1952
|
2017-09-29 10:34 |
2009-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257403
|
- |
|
ascadnetworks
|
password_protector_sd
|
Ascad Networks Password Protector SD 1.3.1 allows remote attackers to bypass authentication and gain administrative access by setting the (1) c7portal and (2) cookname cookies to "admin."
|
CWE-287
Improper Authentication
|
CVE-2009-2003
|
2017-09-29 10:34 |
2009-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257404
|
- |
|
frontisgroup
|
frontis
|
SQL injection vulnerability in bin/aps_browse_sources.php in Frontis 3.9.01.24 allows remote attackers to execute arbitrary SQL commands via the source_class parameter in a browse_classes action.
|
CWE-89
SQL Injection
|
CVE-2009-2013
|
2017-09-29 10:34 |
2009-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257405
|
- |
|
joomla
|
com_school
|
SQL injection vulnerability in the ComSchool (com_school) component 1.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the classid parameter in a showclass action to index.…
|
CWE-89
SQL Injection
|
CVE-2009-2014
|
2017-09-29 10:34 |
2009-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257406
|
- |
|
ideal
|
com_moofaq
|
Directory traversal vulnerability in includes/file_includer.php in the Ideal MooFAQ (com_moofaq) component 1.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the fi…
|
CWE-22
Path Traversal
|
CVE-2009-2015
|
2017-09-29 10:34 |
2009-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257407
|
- |
|
virtuenetz
|
virtue_shopping_mall
|
SQL injection vulnerability in products.php in Virtue Shopping Mall allows remote attackers to execute arbitrary SQL commands via the cid parameter.
|
CWE-89
SQL Injection
|
CVE-2009-2016
|
2017-09-29 10:34 |
2009-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257408
|
- |
|
virtuenetz
|
virtue_book_store
|
SQL injection vulnerability in products.php in Virtue Book Store allows remote attackers to execute arbitrary SQL commands via the cid parameter.
|
CWE-89
SQL Injection
|
CVE-2009-2017
|
2017-09-29 10:34 |
2009-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257409
|
- |
|
jaredeckersley
|
mycars
|
SQL injection vulnerability in admin/index.php in Jared Eckersley MyCars, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the authuserid parameter.
|
CWE-89
SQL Injection
|
CVE-2009-2018
|
2017-09-29 10:34 |
2009-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257410
|
- |
|
virtuenetz
|
virtue_news_manager
|
SQL injection vulnerability in news_detail.php in Virtue News Manager allows remote attackers to execute arbitrary SQL commands via the nid parameter.
|
CWE-89
SQL Injection
|
CVE-2009-2019
|
2017-09-29 10:34 |
2009-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|