256691
|
- |
|
rens_rikkerink
|
fungamez
|
includes/user.php in Fungamez RC1 allows remote attackers to bypass authentication and gain administrative access by setting the user cookie parameter.
|
CWE-287
Improper Authentication
|
CVE-2009-1489
|
2017-09-29 10:34 |
2009-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256692
|
- |
|
webfileexplorer
|
web_file_explorer
|
Web File Explorer 3.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for data/db.mdb.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-1495
|
2017-09-29 10:34 |
2009-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256693
|
- |
|
ijobid
|
com_cmimarketplace
|
Directory traversal vulnerability in the Cmi Marketplace (com_cmimarketplace) component 0.1 for Joomla! allows remote attackers to list arbitrary directories via a .. (dot dot) in the viewit paramete…
|
CWE-22
Path Traversal
|
CVE-2009-1496
|
2017-09-29 10:34 |
2009-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256694
|
- |
|
idb
|
idb
|
Directory traversal vulnerability in inc/profilemain.php in Game Maker 2k Internet Discussion Boards (iDB) 0.2.5 Pre-Alpha SVN 243 allows remote attackers to include and execute arbitrary local files…
|
CWE-22
Path Traversal
|
CVE-2009-1498
|
2017-09-29 10:34 |
2009-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256695
|
- |
|
joomla
|
joomla\! com_mailto
|
SQL injection vulnerability in the MailTo (aka com_mailto) component in Joomla! allows remote attackers to execute arbitrary SQL commands via the article parameter in index.php. NOTE: SecurityFocus …
|
CWE-89
SQL Injection
|
CVE-2009-1499
|
2017-09-29 10:34 |
2009-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256696
|
- |
|
matteoiammarrone
|
s-cms
|
Directory traversal vulnerability in plugin.php in S-Cms 1.1 Stable and 1.5.2 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the page parame…
|
CWE-22
Path Traversal
|
CVE-2009-1502
|
2017-09-29 10:34 |
2009-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256697
|
- |
|
tigerdms
|
tigerdms
|
Multiple SQL injection vulnerabilities in login.php in Tiger Document Management System (DMS) allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.
|
CWE-89
SQL Injection
|
CVE-2009-1503
|
2017-09-29 10:34 |
2009-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256698
|
- |
|
xigla
|
absolute_control_panel_xe
|
Absolute Form Processor XE 1.5 allows remote attackers to bypass authentication and gain administrative access by setting the xlaAFPadmin cookie to "lvl=1&userid=1."
|
CWE-287
Improper Authentication
|
CVE-2009-1504
|
2017-09-29 10:34 |
2009-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256699
|
- |
|
intelliants
|
elitius
|
SQL injection vulnerability in classes/Xp.php in eLitius 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter to banner-details.php.
|
CWE-89
SQL Injection
|
CVE-2009-1506
|
2017-09-29 10:34 |
2009-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256700
|
- |
|
keir_davis
|
x-forum
|
SQL injection vulnerability in the xforum_validateUser function in Common.php in X-Forum 0.6.2 allows remote attackers to execute arbitrary SQL commands, as demonstrated via the cookie_username param…
|
CWE-89
SQL Injection
|
CVE-2009-1508
|
2017-09-29 10:34 |
2009-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|