258931
|
- |
|
cpecreator
|
cp_creator
|
SQL injection vulnerability in index.php in cP Creator 2.7.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the tickets parameter in a support ticke…
|
CWE-89
SQL Injection
|
CVE-2009-3330
|
2017-09-19 10:29 |
2009-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258932
|
- |
|
ddlcms
|
ddl_cms
|
Multiple PHP remote file inclusion vulnerabilities in DDL CMS 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the wwwRoot parameter to (1) header.php, (2) submit.php, (3) submit…
|
CWE-94
Code Injection
|
CVE-2009-3331
|
2017-09-19 10:29 |
2009-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258933
|
- |
|
sopinet
|
com_jbudgetsmagic
|
SQL injection vulnerability in the JBudgetsMagic (com_jbudgetsmagic) component 0.3.2 through 0.4.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the bid parameter in a myb…
|
CWE-89
SQL Injection
|
CVE-2009-3332
|
2017-09-19 10:29 |
2009-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258934
|
- |
|
alibasta
|
com_koesubmit
|
PHP remote file inclusion vulnerability in koesubmit.php in the koeSubmit (com_koesubmit) component 1.0 for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_abso…
|
CWE-94
Code Injection
|
CVE-2009-3333
|
2017-09-19 10:29 |
2009-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258935
|
- |
|
lhacky
|
com_jinc
|
SQL injection vulnerability in the Lhacky! Extensions Cave Joomla! Integrated Newsletters Component (aka JINC or com_jinc) component 0.2 for Joomla! allows remote attackers to execute arbitrary SQL c…
|
CWE-89
SQL Injection
|
CVE-2009-3334
|
2017-09-19 10:29 |
2009-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258936
|
- |
|
turtus
|
turtushout
|
SQL injection vulnerability in the TurtuShout component 0.11 for Joomla! allows remote attackers to execute arbitrary SQL commands via the Name field.
|
CWE-89
SQL Injection
|
CVE-2009-3335
|
2017-09-19 10:29 |
2009-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258937
|
- |
|
phpprobid
|
php_pro_bid
|
SQL injection vulnerability in auction_details.php in PHP Pro Bid allows remote attackers to execute arbitrary SQL commands via the auction_id parameter.
|
CWE-89
SQL Injection
|
CVE-2009-3336
|
2017-09-19 10:29 |
2009-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258938
|
- |
|
effectmatrix
|
magic_morph
|
Stack-based buffer overflow in EffectMatrix (E.M.) Magic Morph 1.95b allows remote attackers to execute arbitrary code via a long string in a .mor file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-3338
|
2017-09-19 10:29 |
2009-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258939
|
- |
|
hotwebscripts
|
hotweb_rentals
|
SQL injection vulnerability in details.asp in HotWeb Rentals allows remote attackers to execute arbitrary SQL commands via the PropId parameter.
|
CWE-89
SQL Injection
|
CVE-2009-3343
|
2017-09-19 10:29 |
2009-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258940
|
- |
|
datavore
|
gyro
|
Cross-site scripting (XSS) vulnerability in Datavore Gyro 5.0 allows remote attackers to inject arbitrary web script or HTML via the cid parameter in a cat action to the home component.
|
CWE-79
Cross-site Scripting
|
CVE-2009-3348
|
2017-09-19 10:29 |
2009-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|