257271
|
- |
|
pad-site-scripts
|
pad_site_scripts
|
Multiple SQL injection vulnerabilities in PAD Site Scripts 3.6 allow remote attackers to execute arbitrary SQL commands via the (1) search parameter to list.php and (2) cat parameter to rss.php.
|
CWE-89
SQL Injection
|
CVE-2009-3190
|
2017-09-19 10:29 |
2009-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257272
|
- |
|
pad-site-scripts
|
pad_site_scripts
|
Multiple cross-site scripting (XSS) vulnerabilities in PAD Site Scripts 3.6 allow remote attackers to inject arbitrary web script or HTML via the cat parameter to (1) rss.php and (2) opml.php.
|
CWE-79
Cross-site Scripting
|
CVE-2009-3191
|
2017-09-19 10:29 |
2009-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257273
|
- |
|
uwix
|
com_digifolio
|
SQL injection vulnerability in the DigiFolio (com_digifolio) component 1.52 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a project action to index.php.
|
CWE-89
SQL Injection
|
CVE-2009-3193
|
2017-09-19 10:29 |
2009-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257274
|
- |
|
uebimiau
|
uebimiau
|
Uebimiau Webmail 3.2.0-2.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database with usernames and password hashes vi…
|
CWE-200
Information Exposure
|
CVE-2009-3199
|
2017-09-19 10:29 |
2009-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257275
|
- |
|
rob_schultz
|
media_player_classic
|
Integer overflow in Media Player Classic 6.4.9 allows user-assisted remote attackers to cause a denial of service (application crash) via a MIDI file (.mid) with a malformed header, which triggers a …
|
CWE-189
Numeric Errors
|
CVE-2009-3201
|
2017-09-19 10:29 |
2009-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257276
|
- |
|
wiccle
|
iwiccle
|
Multiple directory traversal vulnerabilities in iWiccle 1.01, when magic_quotes_gpc is disabled, allow remote attackers to read arbitrary files via a .. (dot dot) in (1) the show parameter to the adm…
|
CWE-22
Path Traversal
|
CVE-2009-3216
|
2017-09-19 10:29 |
2009-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257277
|
- |
|
wiccle
|
iwiccle
|
SQL injection vulnerability in the admin module in iWiccle 1.01 allows remote attackers to execute arbitrary SQL commands via the member_id parameter in an edit_user action to index.php.
|
CWE-89
SQL Injection
|
CVE-2009-3217
|
2017-09-19 10:29 |
2009-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257278
|
- |
|
the-ghost
|
ar_web_content_manager
|
SQL injection vulnerability in control/login.php in AR Web Content Manager (AWCM) 2.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the username pa…
|
CWE-89
SQL Injection
|
CVE-2009-3218
|
2017-09-19 10:29 |
2009-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257279
|
- |
|
the-ghost
|
ar_web_content_manager
|
Directory traversal vulnerability in a.php in AR Web Content Manager (AWCM) 2.1, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot …
|
CWE-22
Path Traversal
|
CVE-2009-3219
|
2017-09-19 10:29 |
2009-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257280
|
- |
|
inoutscripts
|
inout_adserver
|
SQL injection vulnerability in ppc-add-keywords.php in Inout Adserver allows remote authenticated users to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2009-3223
|
2017-09-19 10:29 |
2009-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|