258081
|
- |
|
adaptcms
|
adaptcms
|
Multiple cross-site scripting (XSS) vulnerabilities in index.php in AdaptCMS Lite 1.4 allow remote attackers to inject arbitrary web script or HTML via the (1) url and (2) acuparam parameters, and (3…
|
CWE-79
Cross-site Scripting
|
CVE-2009-0526
|
2017-09-29 10:33 |
2009-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258082
|
- |
|
adaptcms
|
adaptcms
|
PHP remote file inclusion vulnerability in plugins/rss_importer_functions.php in AdaptCMS Lite 1.4 allows remote attackers to execute arbitrary PHP code via a URL in the sitepath parameter.
|
CWE-94
Code Injection
|
CVE-2009-0527
|
2017-09-29 10:33 |
2009-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258083
|
- |
|
rhadrix
|
if-cms
|
SQL injection vulnerability in frame.php in Rhadrix If-CMS 2.07 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2009-0528
|
2017-09-29 10:33 |
2009-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258084
|
- |
|
electrictoad
|
snippetmaster_webpage_editor
|
Cross-site scripting (XSS) vulnerability in index.php in SnippetMaster Webpage Editor 2.2.2 allows remote attackers to inject arbitrary web script or HTML via the language parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2009-0529
|
2017-09-29 10:33 |
2009-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258085
|
- |
|
electrictoad
|
snippetmaster_webpage_editor
|
Multiple PHP remote file inclusion vulnerabilities in SnippetMaster 2.2.2, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) _SESSION[SCRIPT_…
|
CWE-94
Code Injection
|
CVE-2009-0530
|
2017-09-29 10:33 |
2009-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258086
|
- |
|
ontarioabandonedplaces
|
a_better_member-based_asp_photo_gallery
|
SQL injection vulnerability in gallery/view.asp in A Better Member-Based ASP Photo Gallery before 1.2 allows remote attackers to execute arbitrary SQL commands via the entry parameter.
|
CWE-89
SQL Injection
|
CVE-2009-0531
|
2017-09-29 10:33 |
2009-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258087
|
- |
|
ontarioabandonedplaces
|
a_better_member-based_asp_photo_gallery
|
Version 1.2 released which fixed the SQL injection bug. It also properly deletes thumbnails for invalid filetypes (invalid files were removed but the thumbnails remained).
http://www.ontarioabando…
|
CWE-89
SQL Injection
|
CVE-2009-0531
|
2017-09-29 10:33 |
2009-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258088
|
- |
|
flexcms
|
flexcms
|
SQL injection vulnerability in FlexCMS allows remote attackers to execute arbitrary SQL commands via the catId parameter.
|
CWE-89
SQL Injection
|
CVE-2009-0534
|
2017-09-29 10:33 |
2009-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258089
|
- |
|
extrosoft
|
thyme
|
Directory traversal vulnerability in export.php in Thyme 1.3 and earlier, when register_globals is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the export_to parame…
|
CWE-22
Path Traversal
|
CVE-2009-0535
|
2017-09-29 10:33 |
2009-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258090
|
- |
|
ibm
|
aix
|
at in bos.rte.cron on IBM AIX 5.2.0, 5.3.0 through 5.3.9, and 6.1.0 through 6.1.2 allows local users to read arbitrary files via unspecified vectors, related to failure to drop root privileges.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-0536
|
2017-09-29 10:33 |
2009-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|