258421
|
- |
|
al4us
|
mymsg
|
SQL injection vulnerability in Profile.php in MyMsg 1.0.3 allows remote authenticated users to execute arbitrary SQL commands via the uid parameter in a show action.
|
CWE-89
SQL Injection
|
CVE-2009-3528
|
2017-09-19 10:29 |
2009-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258422
|
- |
|
radscripts
|
radbids
|
SQL injection vulnerability in index.php in RadScripts RadBids Gold 4 allows remote attackers to execute arbitrary SQL commands via the fid parameter in a view_forum action, a different vector than C…
|
CWE-89
SQL Injection
|
CVE-2009-3529
|
2017-09-19 10:29 |
2009-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258423
|
- |
|
radscripts
|
radbids
|
Cross-site scripting (XSS) vulnerability in storefront.php in RadScripts RadBids Gold 4 allows remote attackers to inject arbitrary web script or HTML via the mode parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2009-3530
|
2017-09-19 10:29 |
2009-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258424
|
- |
|
universe
|
universe_cms
|
SQL injection vulnerability in vnews.php in Universe CMS 1.0.6 allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2009-3531
|
2017-09-19 10:29 |
2009-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258425
|
- |
|
lionwiki
|
lionwiki
|
Directory traversal vulnerability in index.php in LionWiki 3.0.3, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter.
|
CWE-22
Path Traversal
|
CVE-2009-3534
|
2017-09-19 10:29 |
2009-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258426
|
- |
|
allisclear
|
clear_content
|
Directory traversal vulnerability in image.php in Clear Content 1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the url parameter. NOTE: the researcher also suggests an ana…
|
CWE-22
Path Traversal
|
CVE-2009-3535
|
2017-09-19 10:29 |
2009-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258427
|
- |
|
epicdjsoftware
|
epicvj
|
Multiple stack-based buffer overflows in EpicDJSoftware EpicVJ 1.2.8.0 and 1.3.1.2 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a lon…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-3536
|
2017-09-19 10:29 |
2009-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258428
|
- |
|
epicdjsoftware
|
epicdj
|
Multiple stack-based buffer overflows in EpicDJSoftware EpicDJ 1.3.9.1 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long string in …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-3537
|
2017-09-19 10:29 |
2009-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258429
|
- |
|
phpgenealogy
|
phpgenealogy
|
PHP remote file inclusion vulnerability in CoupleDB.php in PHPGenealogy 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the DataDirectory parameter.
|
CWE-94
Code Injection
|
CVE-2009-3541
|
2017-09-19 10:29 |
2009-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258430
|
- |
|
phenotype-cms
|
phenotype_cms
|
SQL injection vulnerability in _phenotype/admin/login.php in Phenotype CMS before 2.9 allows remote attackers to execute arbitrary SQL commands via the user parameter (aka the login name).
|
CWE-89
SQL Injection
|
CVE-2009-3543
|
2017-09-19 10:29 |
2009-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|