257491
|
- |
|
joost_horward
|
catviz
|
Multiple directory traversal vulnerabilities in index.php in Catviz 0.4.0 Beta 1 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) webpages_form or (2) userman_form paramet…
|
CWE-22
Path Traversal
|
CVE-2009-1748
|
2017-09-29 10:34 |
2009-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257492
|
- |
|
joost_horward
|
catviz
|
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Catviz 0.4.0 beta 1 allow remote attackers to inject arbitrary web script or HTML via the (1) userman_form and (2) webpages_form pa…
|
CWE-79
Cross-site Scripting
|
CVE-2009-1749
|
2017-09-29 10:34 |
2009-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257493
|
- |
|
omnisoftsol
|
vidsharepro
|
Unrestricted file upload vulnerability in VidSharePro allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via unspecified v…
|
NVD-CWE-Other
|
CVE-2009-1750
|
2017-09-29 10:34 |
2009-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257494
|
- |
|
realtywebware
|
realty_web-base
|
SQL injection vulnerability in list_list.php in Realty Webware Technologies Web-Base 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2009-1751
|
2017-09-29 10:34 |
2009-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257495
|
- |
|
exjune
|
office_message_system
|
exJune Office Message System 1 does not properly restrict access to (1) configure.asp and (2) addmessage2.asp, which allows remote attackers to gain privileges a direct request. NOTE: some of these …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-1752
|
2017-09-29 10:34 |
2009-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257496
|
- |
|
xen
|
xen
|
The hypervisor_callback function in Xen, possibly before 3.4.0, as applied to the Linux kernel 2.6.30-rc4, 2.6.18, and probably other versions allows guest user applications to cause a denial of serv…
|
CWE-399
Resource Management Errors
|
CVE-2009-1758
|
2017-09-29 10:34 |
2009-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257497
|
- |
|
rahul
|
dtorrent ctorrent
|
Stack-based buffer overflow in the btFiles::BuildFromMI function (trunk/btfiles.cpp) in Enhanced CTorrent (aka dTorrent) 3.3.2 and probably earlier, and CTorrent 1.3.4, allows remote attackers to cau…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-1759
|
2017-09-29 10:34 |
2009-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257498
|
- |
|
bokecc
|
maxcms
|
SQL injection vulnerability in inc/ajax.asp in MaxCMS 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a digg action.
|
CWE-89
SQL Injection
|
CVE-2009-1764
|
2017-09-29 10:34 |
2009-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257499
|
- |
|
pluck-cms
|
pluck
|
Multiple directory traversal vulnerabilities in pluck 4.6.2, when register_globals is enabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the langpref p…
|
CWE-22
Path Traversal
|
CVE-2009-1765
|
2017-09-29 10:34 |
2009-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257500
|
- |
|
2daybiz
|
template_monster_clone
|
admin/edituser.php in 2daybiz Template Monster Clone does not require administrative authentication, which allows remote attackers to modify arbitrary accounts via the (1) loginname, (2) password, (3…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-1767
|
2017-09-29 10:34 |
2009-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|