258161
|
- |
|
sorinara
|
streaming_audio_player
|
Stack-based buffer overflow in Sorinara Streaming Audio Player (SAP) 0.9 allows remote attackers to execute arbitrary code via a long string in a playlist (.m3u) file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-2568
|
2017-09-19 10:29 |
2009-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258162
|
- |
|
mlffat
|
mlffat
|
SQL injection vulnerability in index.php in Mlffat 2.2 allows remote attackers to execute arbitrary SQL commands via a member cookie in an account editprofile action, a different vector than CVE-2009…
|
CWE-89
SQL Injection
|
CVE-2009-2585
|
2017-09-19 10:29 |
2009-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258163
|
- |
|
runcms
|
myannonces
|
SQL injection vulnerability in the MyAnnonces module for E-Xoopport 3.1 allows remote attackers to execute arbitrary SQL commands via the lid parameter in a viewannonces action to index.php.
|
CWE-89
SQL Injection
|
CVE-2009-2591
|
2017-09-19 10:29 |
2009-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258164
|
- |
|
phpjunkyard
|
gbook
|
SQL injection vulnerability in guestbook.php in PHPJunkYard GBook 1.6 allows remote attackers to execute arbitrary SQL commands via the mes_id parameter.
|
CWE-89
SQL Injection
|
CVE-2009-2592
|
2017-09-19 10:29 |
2009-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258165
|
- |
|
censura
|
censura
|
SQL injection vulnerability in censura.php in Censura 1.16.04 allows remote attackers to execute arbitrary SQL commands via the itemid parameter in a details action.
|
CWE-89
SQL Injection
|
CVE-2009-2593
|
2017-09-19 10:29 |
2009-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258166
|
- |
|
censura
|
censura
|
Cross-site scripting (XSS) vulnerability in censura.php in Censura 1.16.04 allows remote attackers to inject arbitrary web script or HTML via the itemid parameter in a details action.
|
CWE-79
Cross-site Scripting
|
CVE-2009-2594
|
2017-09-19 10:29 |
2009-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258167
|
- |
|
radscripts
|
radclassifieds
|
SQL injection vulnerability in index.php in RadCLASSIFIEDS Gold 2.0 allows remote attackers to execute arbitrary SQL commands via the seller parameter in a search action.
|
CWE-89
SQL Injection
|
CVE-2009-2599
|
2017-09-19 10:29 |
2009-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258168
|
- |
|
akiva
|
webboard
|
Multiple directory traversal vulnerabilities in view.php in Webboard 2.90 beta and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in the topic parameter.
|
CWE-22
Path Traversal
|
CVE-2009-2600
|
2017-09-19 10:29 |
2009-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258169
|
- |
|
joomlaequipment
|
juser
|
SQL injection vulnerability in the Joomlaequipment (aka JUser or com_juser) component 2.0.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a show_profil…
|
CWE-89
SQL Injection
|
CVE-2009-2601
|
2017-09-19 10:29 |
2009-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258170
|
- |
|
r2newsletter
|
r2_newsletter_lite r2_newsletter_pro r2_newsletter_stats
|
R2 Newsletter Lite, Pro, and Stats stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request f…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-2602
|
2017-09-19 10:29 |
2009-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|