257661
|
- |
|
jnmsolutions
|
db_top_sites
|
Static code injection vulnerability in add_reg.php in DB Top Sites 1.0 allows remote attackers to inject arbitrary PHP code via a crafted (1) url and (2) location parameter.
|
CWE-94
Code Injection
|
CVE-2009-2111
|
2017-09-29 10:34 |
2009-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257662
|
- |
|
frank-karau
|
phpfk
|
Directory traversal vulnerability in include/page_bottom.php in phpFK 7.03 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the _FORUM[setting…
|
CWE-22
Path Traversal
|
CVE-2009-2112
|
2017-09-29 10:34 |
2009-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257663
|
- |
|
phportal
|
phportal
|
uye_paneli.php in phPortal 1.0 allows remote attackers to bypass authentication and obtain administrative access by setting the kulladi cookie to a valid username.
|
CWE-287
Improper Authentication
|
CVE-2009-2117
|
2017-09-29 10:34 |
2009-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257664
|
- |
|
tekbase
|
tekbase_all-in-one
|
Multiple SQL injection vulnerabilities in TekBase All-in-One 3.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) ids parameter to admin.php, the (2) y parameter to memb…
|
CWE-89
SQL Injection
|
CVE-2009-2120
|
2017-09-29 10:34 |
2009-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257665
|
- |
|
paolo_palmonari
|
photoracer_plugin_for_wordpress
|
SQL injection vulnerability in viewimg.php in the Paolo Palmonari Photoracer plugin 1.0 for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2009-2122
|
2017-09-29 10:34 |
2009-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257666
|
- |
|
elvinbts
|
elvinbts
|
Multiple SQL injection vulnerabilities in Elvin 1.2.0 allow remote attackers to execute arbitrary SQL commands via the (1) inUser (aka Username) and (2) inPass (aka Password) parameters to (a) inc/lo…
|
CWE-89
SQL Injection
|
CVE-2009-2123
|
2017-09-29 10:34 |
2009-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257667
|
- |
|
elvinbts
|
elvinbts
|
Directory traversal vulnerability in page.php in Elvin 1.2.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the id parameter.
|
CWE-22
Path Traversal
|
CVE-2009-2124
|
2017-09-29 10:34 |
2009-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257668
|
- |
|
elvinbts
|
elvinbts
|
Cross-site scripting (XSS) vulnerability in show_activity.php in Elvin 1.2.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2009-2127
|
2017-09-29 10:34 |
2009-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257669
|
- |
|
elvinbts
|
elvinbts
|
Cross-site request forgery (CSRF) vulnerability in login.php in Elvin 1.2.0 allows remote attackers to hijack the authentication of arbitrary users via a logout action.
|
CWE-352
Origin Validation Error
|
CVE-2009-2129
|
2017-09-29 10:34 |
2009-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257670
|
- |
|
elvinbts
|
elvinbts
|
Elvin 1.2.0 allows remote attackers to read the PHP source code of (1) login.ei, (2) jump_bug.ei, or (3) create_account.ei in inc/ via a direct request.
|
CWE-200
Information Exposure
|
CVE-2009-2130
|
2017-09-29 10:34 |
2009-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|