257731
|
- |
|
keir_davis
|
x-forum
|
SQL injection vulnerability in the xforum_validateUser function in Common.php in X-Forum 0.6.2 allows remote attackers to execute arbitrary SQL commands, as demonstrated via the cookie_username param…
|
CWE-89
SQL Injection
|
CVE-2009-1508
|
2017-09-29 10:34 |
2009-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257732
|
- |
|
myiosoft
|
ajaxportal
|
SQL injection vulnerability in ajaxp_backend.php in MyioSoft AjaxPortal 3.0 allows remote attackers to execute arbitrary SQL commands via the page parameter.
|
CWE-89
SQL Injection
|
CVE-2009-1509
|
2017-09-29 10:34 |
2009-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257733
|
- |
|
koschtit
|
koschtit_image_gallery
|
Multiple directory traversal vulnerabilities in KoschtIT Image Gallery 1.82 allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the file parameter…
|
CWE-22
Path Traversal
|
CVE-2009-1510
|
2017-09-29 10:34 |
2009-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257734
|
- |
|
microsoft
|
windows_xp
|
GDI+ in Microsoft Windows XP SP3 allows remote attackers to cause a denial of service (infinite loop) via a PNG file that contains a certain large btChunkLen value.
|
CWE-399
Resource Management Errors
|
CVE-2009-1511
|
2017-09-29 10:34 |
2009-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257735
|
- |
|
keir_davis
|
x-forum
|
Static code injection vulnerability in X-Forum 0.6.2 allows remote authenticated administrators to inject arbitrary PHP code into Config.php via the adminEMail parameter to SaveConfig.php.
|
CWE-94
Code Injection
|
CVE-2009-1512
|
2017-09-29 10:34 |
2009-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257736
|
- |
|
google
|
chrome
|
Google Chrome 1.0.154.53 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a throw statement with a long exception value.
|
CWE-399
Resource Management Errors
|
CVE-2009-1514
|
2017-09-29 10:34 |
2009-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257737
|
- |
|
icewarp
|
merak_mail_server
|
Stack-based buffer overflow in the IceWarpServer.APIObject ActiveX control in api.dll in IceWarp Merak Mail Server 9.4.1 might allow context-dependent attackers to execute arbitrary code via a large …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-1516
|
2017-09-29 10:34 |
2009-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257738
|
- |
|
pecio-cms
|
pecio_cms
|
Directory traversal vulnerability in index.php in Pecio CMS 1.1.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the language parameter.
|
CWE-22
Path Traversal
|
CVE-2009-1519
|
2017-09-29 10:34 |
2009-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257739
|
- |
|
qsix
|
blusky_cms
|
SQL injection vulnerability in index.php in BluSky CMS allows remote attackers to execute arbitrary SQL commands via the news_id parameter in a read action.
|
CWE-89
SQL Injection
|
CVE-2009-1548
|
2017-09-29 10:34 |
2009-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257740
|
- |
|
agtc
|
agtc_myshop
|
AGTC MyShop 3.2b allows remote attackers to bypass authentication and obtain administrative access setting the log_accept cookie to "correcto."
|
CWE-287
Improper Authentication
|
CVE-2009-1549
|
2017-09-29 10:34 |
2009-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|