258161
|
- |
|
element-it
|
ultimate_uploader
|
Per: http://cwe.mitre.org/data/definitions/434.html
'CWE-434: Unrestricted Upload of File with Dangerous Type'
|
NVD-CWE-Other
|
CVE-2009-4817
|
2017-08-17 10:31 |
2010-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258162
|
- |
|
phpsimplicity
|
simplicity_of_upload
|
Unrestricted file upload vulnerability in upload.php in PHPSimplicity Simplicity oF Upload 1.3.2 allows remote attackers to execute arbitrary PHP code by uploading a file with a double extension, as …
|
NVD-CWE-Other
|
CVE-2009-4818
|
2017-08-17 10:31 |
2010-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258163
|
- |
|
phpsimplicity
|
simplicity_of_upload
|
Per: http://cwe.mitre.org/data/definitions/434.html
'CWE-434: Unrestricted Upload of File with Dangerous Type'
|
NVD-CWE-Other
|
CVE-2009-4818
|
2017-08-17 10:31 |
2010-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258164
|
- |
|
stoverud
|
phphotoalbum
|
Multiple unrestricted file upload vulnerabilities in upload.php in PHPhotoalbum allow remote attackers to execute arbitrary code by uploading a file with a (1) .php.pgif or (2) .php.pjpeg double exte…
|
NVD-CWE-Other
|
CVE-2009-4819
|
2017-08-17 10:31 |
2010-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258165
|
- |
|
stoverud
|
phphotoalbum
|
Per: http://cwe.mitre.org/data/definitions/434.html
'CWE-434: Unrestricted Upload of File with Dangerous Type'
|
NVD-CWE-Other
|
CVE-2009-4819
|
2017-08-17 10:31 |
2010-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258166
|
- |
|
aspindir
|
angelo-emlak
|
Angelo-Emlak 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for veribaze/angelo.mdb.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-4820
|
2017-08-17 10:31 |
2010-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258167
|
- |
|
kasseler-cms
|
kasseler_cms
|
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Kasseler CMS 1.3.4 allow remote attackers to inject arbitrary web script or HTML via the (1) do, (2) id, and (3) uname parameters.
|
CWE-79
Cross-site Scripting
|
CVE-2009-4822
|
2017-08-17 10:31 |
2010-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258168
|
- |
|
8pixel
|
simple_blog
|
8pixel.net Blog 4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for App_Data/sb.mdb.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-4825
|
2017-08-17 10:31 |
2010-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258169
|
- |
|
oracle
|
mysql_connector\/net
|
MySQL Connector/NET before 6.0.4, when using encryption, does not verify SSL certificates during connection, which allows remote attackers to perform a man-in-the-middle attack with a spoofed SSL cer…
|
CWE-20
Improper Input Validation
|
CVE-2009-4833
|
2017-08-17 10:31 |
2010-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258170
|
- |
|
deliantra
|
deliantra
|
Multiple buffer overflows in Deliantra Server before 2.82 allow remote attackers to execute arbitrary code via vectors related to (1) the command_gsay function in server/c_party.C and (2) the book im…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-4846
|
2017-08-17 10:31 |
2010-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|