258091
|
- |
|
evolution
|
evolution
|
Evolution 2.22.3.1 checks S/MIME signatures against a copy of the e-mail text within a signed-data blob, not the copy of the e-mail text displayed to the user, which allows remote attackers to spoof …
|
CWE-310
Cryptographic Issues
|
CVE-2009-0547
|
2017-09-29 10:33 |
2009-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258092
|
- |
|
ninjadesigns
|
mailist
|
Directory traversal vulnerability in send.php in Ninja Designs Mailist 3.0, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary…
|
CWE-22
Path Traversal
|
CVE-2009-0570
|
2017-09-29 10:33 |
2009-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258093
|
- |
|
ninjadesigns
|
mailist
|
admin.php in Ninja Designs Mailist 3.0 stores backup copies of maillist.php under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a di…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-0571
|
2017-09-29 10:33 |
2009-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258094
|
- |
|
cafeengine
|
easycafeengine
|
SQL injection vulnerability in index.php in Easy CafeEngine allows remote attackers to execute arbitrary SQL commands via the catid parameter, a different vector than CVE-2008-4604.
|
CWE-89
SQL Injection
|
CVE-2009-0574
|
2017-09-29 10:33 |
2009-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258095
|
- |
|
ubuntu
|
ubuntu_linux
|
GNOME NetworkManager before 0.7.0.99 does not properly verify privileges for dbus (1) modify and (2) delete requests, which allows local users to change or remove the network connections of arbitrary…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-0578
|
2017-09-29 10:33 |
2009-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258096
|
- |
|
gnome
|
evolution-data-server
|
The ntlm_challenge function in the NTLM SASL authentication mechanism in camel/camel-sasl-ntlm.c in Camel in Evolution Data Server (aka evolution-data-server) 2.24.5 and earlier, and 2.25.92 and earl…
|
CWE-20
Improper Input Validation
|
CVE-2009-0582
|
2017-09-29 10:33 |
2009-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258097
|
- |
|
pnphpbb
|
pnphpbb2
|
Multiple directory traversal vulnerabilities in PNphpBB2 1.2i and earlier allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the ModName parameter to (1) admin_…
|
CWE-22
Path Traversal
|
CVE-2009-0592
|
2017-09-29 10:33 |
2009-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258098
|
- |
|
plxwebdev
|
plx_auto_reminder
|
SQL injection vulnerability in members.php in plx Auto Reminder 3.7 allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a newar action.
|
CWE-89
SQL Injection
|
CVE-2009-0593
|
2017-09-29 10:33 |
2009-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258099
|
- |
|
apmuthu
|
phpskelsite
|
Cross-site scripting (XSS) vulnerability in index.php in phpSkelSite 1.4 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.
|
CWE-79
Cross-site Scripting
|
CVE-2009-0594
|
2017-09-29 10:33 |
2009-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258100
|
- |
|
phpskelsite
|
phpskelsite
|
PHP remote file inclusion vulnerability in skysilver/login.tpl.php in phpSkelSite 1.4, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary …
|
CWE-94
Code Injection
|
CVE-2009-0595
|
2017-09-29 10:33 |
2009-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|