256641
|
- |
|
glfusion
|
glfusion
|
glFusion before 1.1.3 performs authentication with a user-provided password hash instead of a password, which allows remote attackers to gain privileges by obtaining the hash and using it in the glf_…
|
CWE-310
Cryptographic Issues
|
CVE-2009-1283
|
2017-09-29 10:34 |
2009-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256642
|
- |
|
webfileexplorer
|
web_file_explorer
|
body.asp in Web File Explorer 3.1 allows remote attackers to create arbitrary files and execute arbitrary code via the savefile action with a file parameter containing a filename that has an executab…
|
NVD-CWE-noinfo
|
CVE-2009-1314
|
2017-09-29 10:34 |
2009-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256643
|
- |
|
aquacms
|
aqua_cms
|
Multiple SQL injection vulnerabilities in Aqua CMS 1.1, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) userSID cookie parameter to droplets/fu…
|
CWE-89
SQL Injection
|
CVE-2009-1317
|
2017-09-29 10:34 |
2009-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256644
|
- |
|
jamroom
|
jamroom
|
Directory traversal vulnerability in index.php in Jamroom 3.1.2, 3.2.3 through 3.2.6, 4.0.2, and possibly other versions before 3.4.0 allows remote attackers to include arbitrary files via directory …
|
CWE-22
Path Traversal
|
CVE-2009-1318
|
2017-09-29 10:34 |
2009-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256645
|
- |
|
guestcal
|
guest_cal
|
Directory traversal vulnerability in includes/ini.inc.php in GuestCal 2.1 allows remote attackers to include and execute arbitrary files via a .. (dot dot) in the lang parameter to index.php.
|
CWE-22
Path Traversal
|
CVE-2009-1319
|
2017-09-29 10:34 |
2009-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256646
|
- |
|
humayun_shabbir_bhutta
|
asp_product_catalog
|
Cross-site scripting (XSS) vulnerability in search.asp in ASP Product Catalog 1.0 allows remote attackers to inject arbitrary web script or HTML via the keywords parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2009-1321
|
2017-09-29 10:34 |
2009-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256647
|
- |
|
humayun_shabbir_bhutta
|
asp_product_catalog
|
ASP Product Catalog 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing user credentials via a direct…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-1322
|
2017-09-29 10:34 |
2009-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256648
|
- |
|
webfileexplorer
|
web_file_explorer
|
SQL injection vulnerability in body.asp in Web File Explorer 3.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2009-1323
|
2017-09-29 10:34 |
2009-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256649
|
- |
|
mini-stream
|
asx_to_mp3_converter
|
Stack-based buffer overflow in Mini-stream ASX to MP3 Converter 3.0.0.7 allows remote attackers to execute arbitrary code via a long URI in a playlist (.m3u) file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-1324
|
2017-09-29 10:34 |
2009-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256650
|
- |
|
mini-stream
|
ripper
|
Stack-based buffer overflow in Mini-stream Ripper 3.0.1.1 allows remote attackers to execute arbitrary code via a long URI in a playlist (.m3u) file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-1325
|
2017-09-29 10:34 |
2009-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|