257711
|
- |
|
ivano_culmine
|
webportal_cms
|
Multiple directory traversal vulnerabilities in WebPortal CMS 0.8-beta allow remote attackers to (1) read arbitrary files via directory traversal sequences in the lang parameter to libraries/helpdocs…
|
CWE-22
Path Traversal
|
CVE-2009-1445
|
2017-09-29 10:34 |
2009-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257712
|
- |
|
elkagroup
|
image_gallery
|
Unrestricted file upload vulnerability in upload.php in Elkagroup Image Gallery 1.0 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then …
|
CWE-20
Improper Input Validation
|
CVE-2009-1446
|
2017-09-29 10:34 |
2009-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257713
|
- |
|
e-cart
|
free_shopping_cart
|
Unrestricted file upload vulnerability in admin/editor/image.php in e-cart.biz Free Shopping Cart allows remote attackers to execute arbitrary code by uploading a file with an executable extension, t…
|
NVD-CWE-Other
|
CVE-2009-1447
|
2017-09-29 10:34 |
2009-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257714
|
- |
|
coolplayer
|
coolplayer
|
Stack-based buffer overflow in PortableApps CoolPlayer Portable (aka CoolPlayer+ Portable) 2.19.1 allows remote attackers to execute arbitrary code via a skin file (skin.ini) with a large PlaylistSki…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-1449
|
2017-09-29 10:34 |
2009-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257715
|
- |
|
bluevirus-design
|
sma-db
|
PHP remote file inclusion vulnerability in format.php in SMA-DB 0.3.12 allows remote attackers to execute arbitrary PHP code via a URL in the _page_content parameter.
|
CWE-94
Code Injection
|
CVE-2009-1450
|
2017-09-29 10:34 |
2009-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257716
|
- |
|
bluevirus-design
|
sma-db
|
Cross-site scripting (XSS) vulnerability in startpage.php in SMA-DB 0.3.12 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.
|
CWE-79
Cross-site Scripting
|
CVE-2009-1451
|
2017-09-29 10:34 |
2009-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257717
|
- |
|
bluevirus-design
|
sma-db
|
Multiple PHP remote file inclusion vulnerabilities in theme/format.php in SMA-DB 0.3.13 allow remote attackers to execute arbitrary PHP code via a URL in the (1) _page_css and (2) _page_javascript pa…
|
CWE-94
Code Injection
|
CVE-2009-1452
|
2017-09-29 10:34 |
2009-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257718
|
- |
|
studiolounge
|
address_book
|
Unrestricted file upload vulnerability in upload-file.php in Adam Patterson Studio Lounge Address Book 2.5, as reachable from index2.php, allows remote attackers to execute arbitrary code by uploadin…
|
NVD-CWE-Other
|
CVE-2009-1483
|
2017-09-29 10:34 |
2009-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257719
|
- |
|
ninjadesigns
|
flatchat
|
Directory traversal vulnerability in pmscript.php in Flatchat 3.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the with parameter.
|
CWE-22
Path Traversal
|
CVE-2009-1486
|
2017-09-29 10:34 |
2009-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257720
|
- |
|
rens_rikkerink
|
fungamez
|
SQL injection vulnerability in pages/login.php in FunGamez RC1 allows remote attackers to execute arbitrary SQL commands via the login_user (aka username) parameter. NOTE: some of these details are …
|
CWE-89
SQL Injection
|
CVE-2009-1487
|
2017-09-29 10:34 |
2009-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|