257431
|
- |
|
com_jumi
|
com_jumi
|
SQL injection vulnerability in the Jumi (com_jumi) component 2.0.3 and possibly other versions for Joomla allows remote attackers to execute arbitrary SQL commands via the fileid parameter to index.p…
|
CWE-89
SQL Injection
|
CVE-2009-2102
|
2017-09-29 10:34 |
2009-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257432
|
- |
|
jnmsolutions
|
db_top_sites
|
Multiple directory traversal vulnerabilities in DB Top Sites 1.0, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the u pa…
|
CWE-22
Path Traversal
|
CVE-2009-2110
|
2017-09-29 10:34 |
2009-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257433
|
- |
|
jnmsolutions
|
db_top_sites
|
Static code injection vulnerability in add_reg.php in DB Top Sites 1.0 allows remote attackers to inject arbitrary PHP code via a crafted (1) url and (2) location parameter.
|
CWE-94
Code Injection
|
CVE-2009-2111
|
2017-09-29 10:34 |
2009-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257434
|
- |
|
frank-karau
|
phpfk
|
Directory traversal vulnerability in include/page_bottom.php in phpFK 7.03 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the _FORUM[setting…
|
CWE-22
Path Traversal
|
CVE-2009-2112
|
2017-09-29 10:34 |
2009-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257435
|
- |
|
phportal
|
phportal
|
uye_paneli.php in phPortal 1.0 allows remote attackers to bypass authentication and obtain administrative access by setting the kulladi cookie to a valid username.
|
CWE-287
Improper Authentication
|
CVE-2009-2117
|
2017-09-29 10:34 |
2009-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257436
|
- |
|
tekbase
|
tekbase_all-in-one
|
Multiple SQL injection vulnerabilities in TekBase All-in-One 3.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) ids parameter to admin.php, the (2) y parameter to memb…
|
CWE-89
SQL Injection
|
CVE-2009-2120
|
2017-09-29 10:34 |
2009-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257437
|
- |
|
paolo_palmonari
|
photoracer_plugin_for_wordpress
|
SQL injection vulnerability in viewimg.php in the Paolo Palmonari Photoracer plugin 1.0 for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2009-2122
|
2017-09-29 10:34 |
2009-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257438
|
- |
|
elvinbts
|
elvinbts
|
Multiple SQL injection vulnerabilities in Elvin 1.2.0 allow remote attackers to execute arbitrary SQL commands via the (1) inUser (aka Username) and (2) inPass (aka Password) parameters to (a) inc/lo…
|
CWE-89
SQL Injection
|
CVE-2009-2123
|
2017-09-29 10:34 |
2009-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257439
|
- |
|
elvinbts
|
elvinbts
|
Directory traversal vulnerability in page.php in Elvin 1.2.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the id parameter.
|
CWE-22
Path Traversal
|
CVE-2009-2124
|
2017-09-29 10:34 |
2009-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257440
|
- |
|
elvinbts
|
elvinbts
|
Cross-site scripting (XSS) vulnerability in show_activity.php in Elvin 1.2.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2009-2127
|
2017-09-29 10:34 |
2009-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|