257551
|
- |
|
gscripts
|
dns_tools
|
dig.php in GScripts.net DNS Tools allows remote attackers to execute arbitrary commands via shell metacharacters in the ns parameter.
|
CWE-78
OS Command
|
CVE-2009-1916
|
2017-09-29 10:34 |
2009-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257552
|
- |
|
gstreamer
|
good_plug-ins
|
Multiple integer overflows in the (1) user_info_callback, (2) user_endrow_callback, and (3) gst_pngdec_task functions (ext/libpng/gstpngdec.c) in GStreamer Good Plug-ins (aka gst-plugins-good or gstr…
|
CWE-189
Numeric Errors
|
CVE-2009-1932
|
2017-09-29 10:34 |
2009-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257553
|
- |
|
phpeasycode
|
pad_site_scripts
|
PAD Site Scripts 3.6 stores sensitive information under the web document root with insufficient access control, which allows remote attackers to download the database and obtain sensitive information…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-1941
|
2017-09-29 10:34 |
2009-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257554
|
- |
|
aimp
|
aimp
|
Stack-based buffer overflow in AIMP 2.51 build 330 allows remote attackers to execute arbitrary code via an MP3 file with a long ID3 tag.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-1944
|
2017-09-29 10:34 |
2009-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257555
|
- |
|
tzo
|
webcal
|
SQL injection vulnerability in webCal3_detail.asp in WebCal 3.04 allows remote attackers to execute arbitrary SQL commands via the event_id parameter.
|
CWE-89
SQL Injection
|
CVE-2009-1945
|
2017-09-29 10:34 |
2009-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257556
|
- |
|
adaptbb
|
adaptbb
|
PHP remote file inclusion vulnerability in latestposts.php in AdaptBB 1.0, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the forumspath paramete…
|
CWE-94
Code Injection
|
CVE-2009-1946
|
2017-09-29 10:34 |
2009-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257557
|
- |
|
newsboard
|
unclassified_newsboard
|
SQL injection vulnerability in the UnbDbEncode function in unb_lib/database.lib.php in Unclassified NewsBoard (UNB) 1.6.4 allows remote attackers to execute arbitrary SQL commands via the Query param…
|
CWE-89
SQL Injection
|
CVE-2009-1947
|
2017-09-29 10:34 |
2009-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257558
|
- |
|
unclassified
|
newsboard
|
Multiple directory traversal vulnerabilities in forum.php in Unclassified NewsBoard (UNB) 1.6.4, when register_globals is enabled and magic_quotes_gpc is disabled, allow remote attackers to (1) read …
|
CWE-22
Path Traversal
|
CVE-2009-1948
|
2017-09-29 10:34 |
2009-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257559
|
- |
|
unclassified
|
newsboard
|
import_wbb1.php in Unclassified NewsBoard (UNB) 1.6.4 allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message.
|
CWE-200
Information Exposure
|
CVE-2009-1949
|
2017-09-29 10:34 |
2009-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257560
|
- |
|
ahmet_donmez
|
webeyes_guest_book
|
SQL injection vulnerability in yorum.asp in WebEyes Guest Book 3 allows remote attackers to execute arbitrary SQL commands via the mesajid parameter.
|
CWE-89
SQL Injection
|
CVE-2009-1950
|
2017-09-29 10:34 |
2009-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|