258281
|
- |
|
andrew_simpson
|
webcollab
|
Multiple cross-site request forgery (CSRF) vulnerabilities in WebCollab before 2.50 (aka Billy Goat) allow remote attackers to hijack the authentication of administrators for requests that change an …
|
CWE-352
Origin Validation Error
|
CVE-2009-1455
|
2017-08-17 10:30 |
2009-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258282
|
- |
|
evolution-extreme
|
nuke_evolution_xtreme
|
Cross-site scripting (XSS) vulnerability in player.php in Nuke Evolution Xtreme 2.x allows remote attackers to inject arbitrary web script or HTML via the defaultVisualExt parameter. NOTE: the prove…
|
CWE-79
Cross-site Scripting
|
CVE-2009-1457
|
2017-08-17 10:30 |
2009-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258283
|
- |
|
razorcms
|
razorcms
|
Multiple cross-site scripting (XSS) vulnerabilities in admin/index.php in razorCMS before 0.4 allow remote attackers to inject arbitrary web script or HTML via (1) the slab parameter in an edit actio…
|
CWE-79
Cross-site Scripting
|
CVE-2009-1458
|
2017-08-17 10:30 |
2009-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258284
|
- |
|
razorcms
|
razorcms
|
Cross-site request forgery (CSRF) vulnerability in razorCMS before 0.4 allows remote attackers to hijack the authentication of administrators for requests that create a web page containing PHP code.
|
CWE-352
Origin Validation Error
|
CVE-2009-1459
|
2017-08-17 10:30 |
2009-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258285
|
- |
|
razorcms
|
razorcms
|
razorCMS before 0.4 uses weak permissions for (1) admin/core/admin_config.php, which allows local users to obtain the administrator's password hash and FTP user credentials; and (2) the root director…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-1460
|
2017-08-17 10:30 |
2009-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258286
|
- |
|
razorcms
|
razorcms
|
Cross-site scripting (XSS) vulnerability in the Create New Page form in razorCMS 0.3 RC2 and earlier allows remote authenticated users to inject arbitrary web script or HTML via the Page Title field.
|
CWE-79
Cross-site Scripting
|
CVE-2009-1461
|
2017-08-17 10:30 |
2009-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258287
|
- |
|
razorcms
|
razorcms
|
The Security Manager in razorCMS before 0.4 does not verify the permissions of every file owned by the apache user account, which is inconsistent with the documentation and allows local users to have…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-1462
|
2017-08-17 10:30 |
2009-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258288
|
- |
|
razorcms
|
razorcms
|
Static code injection vulnerability in razorCMS before 0.4 allows remote attackers to inject arbitrary PHP code into any page by saving content as a .php file.
|
CWE-94
Code Injection
|
CVE-2009-1463
|
2017-08-17 10:30 |
2009-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258289
|
- |
|
darren_reed
|
ipfilter
|
Buffer overflow in lib/load_http.c in ippool in Darren Reed IPFilter (aka IP Filter) 4.1.31 allows local users to gain privileges via vectors involving a long hostname in a URL.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-1476
|
2017-08-17 10:30 |
2009-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258290
|
- |
|
sun
|
opensolaris solaris
|
Multiple unspecified vulnerabilities in the DTrace ioctl handlers in Sun Solaris 10, and OpenSolaris before snv_114, allow local users to cause a denial of service (panic) via unknown vectors.
|
NVD-CWE-noinfo
|
CVE-2009-1478
|
2017-08-17 10:30 |
2009-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|