257681
|
- |
|
campusvirtualcomputrade
|
campus_virtual-lms
|
Multiple cross-site request forgery (CSRF) vulnerabilities in Campus Virtual-LMS allow (1) remote attackers to hijack the authentication of arbitrary users for requests that terminate a session via l…
|
CWE-352
Origin Validation Error
|
CVE-2009-2150
|
2017-09-29 10:34 |
2009-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257682
|
- |
|
adaptweb
|
adaptweb
|
Directory traversal vulnerability in index.php in AdaptWeb 0.9.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the newlang parameter.
|
CWE-22
Path Traversal
|
CVE-2009-2151
|
2017-09-29 10:34 |
2009-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257683
|
- |
|
isabela_gasparini
|
adaptweb
|
SQL injection vulnerability in a_index.php in AdaptWeb 0.9.2 allows remote attackers to execute arbitrary SQL commands via the CodigoDisciplina parameter in a TopicosCadastro1 action.
|
CWE-89
SQL Injection
|
CVE-2009-2152
|
2017-09-29 10:34 |
2009-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257684
|
- |
|
sappy.dk
|
impleo_music_collection
|
Cross-site scripting (XSS) vulnerability in index.php in Impleo Music Collection 2.0 allows remote attackers to inject arbitrary web script or HTML via the sort parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2009-2153
|
2017-09-29 10:34 |
2009-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257685
|
- |
|
sappy.dk
|
impleo_music_collection
|
SQL injection vulnerability in admin/login.php in Impleo Music Collection 2.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the username parameter.
|
CWE-89
SQL Injection
|
CVE-2009-2154
|
2017-09-29 10:34 |
2009-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257686
|
- |
|
egyplus
|
7ammel
|
Multiple SQL injection vulnerabilities in cpanel/login.php in EgyPlus 7ammel (aka 7ml) 1.0.1 and earlier, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands v…
|
CWE-89
SQL Injection
|
CVE-2009-2167
|
2017-09-29 10:34 |
2009-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257687
|
- |
|
dream
|
radio_and_tv_player_addon_for_vbulletin
|
Cross-site scripting (XSS) vulnerability in forum/radioandtv.php in the Radio and TV Player addon for vBulletin allows remote registered users to inject arbitrary web script or HTML via the station p…
|
CWE-79
Cross-site Scripting
|
CVE-2009-2172
|
2017-09-29 10:34 |
2009-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257688
|
- |
|
gameis
|
carom3d
|
The LAN game feature in Carom3D 5.06 allows remote authenticated users to cause a denial of service (application hang) via a crafted HTTP request to TCP port 28012.
|
CWE-399
Resource Management Errors
|
CVE-2009-2173
|
2017-09-29 10:34 |
2009-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257689
|
- |
|
fuzzylime
|
fuzzylime_cms
|
Multiple directory traversal vulnerabilities in fuzzylime (cms) 3.03a and earlier, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via directory…
|
CWE-22
Path Traversal
|
CVE-2009-2176
|
2017-09-29 10:34 |
2009-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257690
|
- |
|
fuzzylime
|
fuzzylime_cms
|
code/display.php in fuzzylime (cms) 3.03a and earlier, when magic_quotes_gpc is disabled, allows remote attackers to conduct directory traversal attacks and overwrite arbitrary files via a "....//" (…
|
CWE-22
Path Traversal
|
CVE-2009-2177
|
2017-09-29 10:34 |
2009-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|