258001
|
- |
|
gravityboardx
|
gravity_board_x
|
Static code injection vulnerability in forms/ajax/configure.php in Gravity Board X (GBX) 2.0 BETA allows remote attackers to inject arbitrary PHP code into config.php via the configure action to inde…
|
CWE-94
Code Injection
|
CVE-2009-1278
|
2017-09-29 10:34 |
2009-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258002
|
- |
|
glfusion
|
glfusion
|
SQL injection vulnerability in private/system/lib-session.php in glFusion 1.1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the glf_session cookie parameter.
|
CWE-89
SQL Injection
|
CVE-2009-1282
|
2017-09-29 10:34 |
2009-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258003
|
- |
|
glfusion
|
glfusion
|
glFusion before 1.1.3 performs authentication with a user-provided password hash instead of a password, which allows remote attackers to gain privileges by obtaining the hash and using it in the glf_…
|
CWE-310
Cryptographic Issues
|
CVE-2009-1283
|
2017-09-29 10:34 |
2009-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258004
|
- |
|
webfileexplorer
|
web_file_explorer
|
body.asp in Web File Explorer 3.1 allows remote attackers to create arbitrary files and execute arbitrary code via the savefile action with a file parameter containing a filename that has an executab…
|
NVD-CWE-noinfo
|
CVE-2009-1314
|
2017-09-29 10:34 |
2009-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258005
|
- |
|
aquacms
|
aqua_cms
|
Multiple SQL injection vulnerabilities in Aqua CMS 1.1, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) userSID cookie parameter to droplets/fu…
|
CWE-89
SQL Injection
|
CVE-2009-1317
|
2017-09-29 10:34 |
2009-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258006
|
- |
|
jamroom
|
jamroom
|
Directory traversal vulnerability in index.php in Jamroom 3.1.2, 3.2.3 through 3.2.6, 4.0.2, and possibly other versions before 3.4.0 allows remote attackers to include arbitrary files via directory …
|
CWE-22
Path Traversal
|
CVE-2009-1318
|
2017-09-29 10:34 |
2009-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258007
|
- |
|
guestcal
|
guest_cal
|
Directory traversal vulnerability in includes/ini.inc.php in GuestCal 2.1 allows remote attackers to include and execute arbitrary files via a .. (dot dot) in the lang parameter to index.php.
|
CWE-22
Path Traversal
|
CVE-2009-1319
|
2017-09-29 10:34 |
2009-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258008
|
- |
|
humayun_shabbir_bhutta
|
asp_product_catalog
|
Cross-site scripting (XSS) vulnerability in search.asp in ASP Product Catalog 1.0 allows remote attackers to inject arbitrary web script or HTML via the keywords parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2009-1321
|
2017-09-29 10:34 |
2009-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258009
|
- |
|
humayun_shabbir_bhutta
|
asp_product_catalog
|
ASP Product Catalog 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing user credentials via a direct…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-1322
|
2017-09-29 10:34 |
2009-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258010
|
- |
|
webfileexplorer
|
web_file_explorer
|
SQL injection vulnerability in body.asp in Web File Explorer 3.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2009-1323
|
2017-09-29 10:34 |
2009-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|