258611
|
- |
|
unleashedmind
|
img_assist
|
The Image Assist module 5.x-1.x before 5.x-1.8, 5.x-2.x before 2.0-alpha4, 6.x-1.x before 6.x-1.1, 6.x-2.x before 2.0-alpha4, and 6.x-3.x-dev before 2009-07-15, a module for Drupal, does not properly…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-4558
|
2017-08-17 10:31 |
2010-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258612
|
- |
|
nanwich
|
submitted_by
|
Cross-site scripting (XSS) vulnerability in the Submitted By module 6.x before 6.x-1.3 for Drupal allows remote authenticated users, with "administer content types" privileges, to inject arbitrary we…
|
CWE-79
Cross-site Scripting
|
CVE-2009-4559
|
2017-08-17 10:31 |
2010-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258613
|
- |
|
zenphoto
|
zenphoto
|
SQL injection vulnerability in index.php in Zenphoto 1.2.5 allows remote attackers to execute arbitrary SQL commands via the title parameter in a news action. NOTE: the provenance of this informatio…
|
CWE-89
SQL Injection
|
CVE-2009-4566
|
2017-08-17 10:31 |
2010-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258614
|
- |
|
viscacha
|
viscacha
|
Multiple cross-site scripting (XSS) vulnerabilities in editprofile.php in Viscacha 0.8 Gold allow remote authenticated users to inject arbitrary web script or HTML via the (1) skype, (2) yahoo, (3) a…
|
CWE-79
Cross-site Scripting
|
CVE-2009-4567
|
2017-08-17 10:31 |
2010-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258615
|
- |
|
elkagroup
|
image_gallery
|
SQL injection vulnerability in elkagroup Image Gallery allows remote attackers to execute arbitrary SQL commands via the id parameter to the default URI under news/.
|
CWE-89
SQL Injection
|
CVE-2009-4569
|
2017-08-17 10:31 |
2010-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258616
|
- |
|
joomlabear
|
mod_joomulus
|
Multiple cross-site scripting (XSS) vulnerabilities in the Joomulus (mod_joomulus) module 2.0 for Joomla! allow remote attackers to inject arbitrary web script or HTML via the tagcloud parameter in a…
|
CWE-79
Cross-site Scripting
|
CVE-2009-4573
|
2017-08-17 10:31 |
2010-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258617
|
- |
|
i-escorts
|
i-escorts_directory_script
|
SQL injection vulnerability in country_escorts.php in I-Escorts Directory Script allows remote attackers to execute arbitrary SQL commands via the country_id parameter.
|
CWE-89
SQL Injection
|
CVE-2009-4574
|
2017-08-17 10:31 |
2010-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258618
|
- |
|
qproje
|
com_qpersonel
|
Cross-site scripting (XSS) vulnerability in the Q-Personel (com_qpersonel) component 1.0.2 RC2 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the personel_sira paramet…
|
CWE-79
Cross-site Scripting
|
CVE-2009-4575
|
2017-08-17 10:31 |
2010-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258619
|
- |
|
cmstactics
|
com_beeheard
|
SQL injection vulnerability in the BeeHeard (com_beeheard) component 1.x for Joomla! allows remote attackers to execute arbitrary SQL commands via the category_id parameter in a suggestions action to…
|
CWE-89
SQL Injection
|
CVE-2009-4576
|
2017-08-17 10:31 |
2010-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258620
|
- |
|
facileforms
|
facileforms
|
Cross-site scripting (XSS) vulnerability in the Facileforms (com_facileforms) component for Joomla! and Mambo allows remote attackers to inject arbitrary web script or HTML via the Itemid parameter t…
|
CWE-79
Cross-site Scripting
|
CVE-2009-4578
|
2017-08-17 10:31 |
2010-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|