258201
|
- |
|
sun
|
virtualbox
|
Unspecified vulnerability in Sun VirtualBox 3.0.0 and 3.0.2 allows guest OS users to cause a denial of service (host OS reboot) via unknown vectors.
|
NVD-CWE-noinfo
|
CVE-2009-2714
|
2017-09-19 10:29 |
2009-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258202
|
- |
|
sun
|
virtualbox
|
Sun VirtualBox 2.2 through 3.0.2 r49928 allows guest OS users to cause a denial of service (Linux host OS reboot) via a sysenter instruction.
|
CWE-20
Improper Input Validation
|
CVE-2009-2715
|
2017-09-19 10:29 |
2009-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258203
|
- |
|
sun-jester
|
opennews
|
SQL injection vulnerability in admin.php in sun-jester OpenNews 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the username parameter.
|
CWE-89
SQL Injection
|
CVE-2009-2735
|
2017-09-19 10:29 |
2009-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258204
|
- |
|
sun-jester
|
opennews
|
Static code injection vulnerability in admin.php in sun-jester OpenNews 1.0 allows remote authenticated administrators to inject arbitrary PHP code into config.php via the "Overall Width" field in a …
|
CWE-94
Code Injection
|
CVE-2009-2736
|
2017-09-19 10:29 |
2009-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258205
|
- |
|
dd-wrt
|
dd-wrt
|
httpd.c in httpd in the management GUI in DD-WRT 24 sp1, and other versions before build 12533, allows remote attackers to execute arbitrary commands via shell metacharacters in a request to a cgi-bi…
|
CWE-20
Improper Input Validation
|
CVE-2009-2765
|
2017-09-19 10:29 |
2009-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258206
|
- |
|
dd-wrt
|
dd-wrt
|
httpd.c in httpd in the management GUI in DD-WRT 24 sp1 does not require administrative authentication for programs under cgi-bin/, which allows remote attackers to change settings via HTTP requests.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-2766
|
2017-09-19 10:29 |
2009-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258207
|
- |
|
ultrize
|
timesheet
|
PHP remote file inclusion vulnerability in include/timesheet.php in Ultrize TimeSheet 1.2.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the c…
|
CWE-94
Code Injection
|
CVE-2009-2769
|
2017-09-19 10:29 |
2009-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258208
|
- |
|
powerupload
|
powerupload
|
PowerUpload 2.4 allows remote attackers to bypass authentication and gain administrative access via a MIME encoded value of admin for the myadminname cookie.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-2770
|
2017-09-19 10:29 |
2009-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258209
|
- |
|
shop-020
|
php_paid_4_mail_script
|
PHP remote file inclusion vulnerability in home.php in PHP Paid 4 Mail Script allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.
|
CWE-94
Code Injection
|
CVE-2009-2773
|
2017-09-19 10:29 |
2009-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258210
|
- |
|
php-paid4mail
|
php-paid4mail
|
SQL injection vulnerability in paidbanner.php in PHP Paid 4 Mail Script allows remote attackers to execute arbitrary SQL commands via the ID parameter.
|
CWE-89
SQL Injection
|
CVE-2009-2774
|
2017-09-19 10:29 |
2009-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|