257761
|
- |
|
teraway
|
linktracker
|
Teraway LinkTracker 1.0 allows remote attackers to bypass authentication and gain administrative access via a userid=1&lvl=1 value for the twLTadmin cookie.
|
CWE-287
Improper Authentication
|
CVE-2009-1617
|
2017-09-29 10:34 |
2009-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257762
|
- |
|
teraway
|
livehelp
|
Teraway LiveHelp 2.0 allows remote attackers to bypass authentication and gain administrative access via a pwd=&lvl=1&usr=&alias=admin&userid=1 value for the TWLHadmin cookie.
|
CWE-287
Improper Authentication
|
CVE-2009-1618
|
2017-09-29 10:34 |
2009-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257763
|
- |
|
teraway
|
filestream
|
Teraway FileStream 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the twFSadmin cookie to 1.
|
CWE-287
Improper Authentication
|
CVE-2009-1619
|
2017-09-29 10:34 |
2009-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257764
|
- |
|
ecshop
|
ecshop
|
SQL injection vulnerability in user.php in EcShop 2.5.0 allows remote attackers to execute arbitrary SQL commands via the order_sn parameter in an order_query action.
|
CWE-89
SQL Injection
|
CVE-2009-1622
|
2017-09-29 10:34 |
2009-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257765
|
- |
|
dew-code
|
dew-newphplinks
|
Cross-site scripting (XSS) vulnerability in index.php in Dew-NewPHPLinks 2.0 allows remote attackers to inject arbitrary web script or HTML via the PID parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2009-1623
|
2017-09-29 10:34 |
2009-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257766
|
- |
|
dew-code
|
dew-newphplinks
|
Directory traversal vulnerability in index.php in Dew-NewPHPLinks 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the show parameter.
|
CWE-22
Path Traversal
|
CVE-2009-1624
|
2017-09-29 10:34 |
2009-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257767
|
- |
|
davlin
|
thickbox_gallery
|
Directory traversal vulnerability in index.php in Thickbox Gallery 2 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the ln parameter.
|
CWE-22
Path Traversal
|
CVE-2009-1625
|
2017-09-29 10:34 |
2009-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257768
|
- |
|
will_kraft
|
ez-blog
|
SQL injection vulnerability in public/specific.php in EZ-Blog before Beta 2 20090427, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the category par…
|
CWE-89
SQL Injection
|
CVE-2009-1626
|
2017-09-29 10:34 |
2009-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257769
|
- |
|
sdp_multimedia
|
streaming_download_project
|
Stack-based buffer overflow in Streaming Download Project (SDP) Downloader 2.3.0 allows remote attackers to execute arbitrary code via a long .asf URL in the HREF attribute of a REF element in a .asx…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-1627
|
2017-09-29 10:34 |
2009-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257770
|
- |
|
ipsec-tools
|
ipsec-tools
|
Multiple memory leaks in Ipsec-tools before 0.7.2 allow remote attackers to cause a denial of service (memory consumption) via vectors involving (1) signature verification during user authentication …
|
CWE-399
Resource Management Errors
|
CVE-2009-1632
|
2017-09-29 10:34 |
2009-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|