257021
|
- |
|
sirini
|
grboard
|
Multiple PHP remote file inclusion vulnerabilities in GRBoard 1.8, when register_globals is enabled and magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary PHP code via a URL in…
|
CWE-94
Code Injection
|
CVE-2009-0444
|
2017-09-29 10:33 |
2009-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257022
|
- |
|
syntax_desktop
|
syntax_desktop
|
Directory traversal vulnerability in admin/modules/aa/preview.php in Syntax Desktop 2.7 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the synTarget parame…
|
CWE-22
Path Traversal
|
CVE-2009-0448
|
2017-09-29 10:33 |
2009-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257023
|
- |
|
blazevideo
|
hdtv_player
|
Stack-based buffer overflow in BlazeVideo HDTV Player 3.5 and earlier allows remote attackers to execute arbitrary code via a long string in a playlist (aka .plf) file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-0450
|
2017-09-29 10:33 |
2009-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257024
|
- |
|
skalinks
|
skalinks
|
SQL injection vulnerability in Skalfa SkaLinks 1.5 allows remote attackers to execute arbitrary SQL commands via the Admin name field to the default URI under admin/.
|
CWE-89
SQL Injection
|
CVE-2009-0451
|
2017-09-29 10:33 |
2009-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257025
|
- |
|
onlinegrades
|
online_grades
|
Multiple SQL injection vulnerabilities in parents/login.php in Online Grades 3.2.4, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) uname or (2…
|
CWE-89
SQL Injection
|
CVE-2009-0452
|
2017-09-29 10:33 |
2009-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257026
|
- |
|
onlinegrades
|
online_grades
|
Online Grades 3.2.4 allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function.
|
CWE-200
Information Exposure
|
CVE-2009-0453
|
2017-09-29 10:33 |
2009-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257027
|
- |
|
dmxready
|
online_notebook_manager
|
Multiple SQL injection vulnerabilities in DMXReady Online Notebook Manager 1.1 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password field. NOTE: some third p…
|
CWE-89
SQL Injection
|
CVE-2009-0454
|
2017-09-29 10:33 |
2009-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257028
|
- |
|
sourdough
|
sourdough
|
PHP remote file inclusion vulnerability in examples/example_clientside_javascript.php in patForms, as used in Sourdough 0.3.5, allows remote attackers to execute arbitrary PHP code via a URL in the n…
|
CWE-94
Code Injection
|
CVE-2009-0456
|
2017-09-29 10:33 |
2009-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257029
|
- |
|
magtrb
|
aja_portal
|
Multiple directory traversal vulnerabilities in AJA Portal 1.2 allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the currentlang parameter to ad…
|
CWE-22
Path Traversal
|
CVE-2009-0457
|
2017-09-29 10:33 |
2009-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257030
|
- |
|
clicktech
|
clickcart
|
Multiple SQL injection vulnerabilities in customer_login_check.asp in ClickTech ClickCart 6.0 allow remote attackers to execute arbitrary SQL commands via (1) the txtEmail parameter (aka E-MAIL field…
|
CWE-89
SQL Injection
|
CVE-2009-0462
|
2017-09-29 10:33 |
2009-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|