257411
|
- |
|
ksplayer
|
ksp_sound_player
|
Stack-based buffer overflow in KSP Sound Player 2009 R2 and R2.1 allows remote attackers to execute arbitrary code via a long string in a .m3u playlist file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-3670
|
2017-09-19 10:29 |
2009-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257412
|
- |
|
ebayclonescript
|
ebay_clone
|
Multiple SQL injection vulnerabilities in Ebay Clone 2009 allow remote attackers to execute arbitrary SQL commands via the (1) user_id parameter to feedback.php; and the item_id parameter to (2) view…
|
CWE-89
SQL Injection
|
CVE-2009-3712
|
2017-09-19 10:29 |
2009-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257413
|
- |
|
morcego
|
morcegocms
|
SQL injection vulnerability in fichero.php in MorcegoCMS 1.7.6 and earlier allows remote attackers to execute arbitrary SQL commands via the query string.
|
CWE-89
SQL Injection
|
CVE-2009-3713
|
2017-09-19 10:29 |
2009-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257414
|
- |
|
maniacomputer
|
mcshoutbox
|
Cross-site scripting (XSS) vulnerability in admin_login.php in MCshoutbox 1.1 allows remote attackers to inject arbitrary web script or HTML via the loginerror parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2009-3714
|
2017-09-19 10:29 |
2009-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257415
|
- |
|
maniacomputer
|
mcshoutbox
|
Multiple SQL injection vulnerabilities in scr_login.php in MCshoutbox 1.1, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) pas…
|
CWE-89
SQL Injection
|
CVE-2009-3715
|
2017-09-19 10:29 |
2009-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257416
|
- |
|
maniacomputer
|
mcshoutbox
|
Unrestricted file upload vulnerability in admin.php in MCshoutbox 1.1 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it v…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-3716
|
2017-09-19 10:29 |
2009-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257417
|
- |
|
lucvil
|
patplayer
|
Heap-based buffer overflow in LucVil PatPlayer 3.9 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long URI in a playlist (.m3u) file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-3717
|
2017-09-19 10:29 |
2009-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257418
|
- |
|
davethewebguy
|
battle_blog
|
SQL injection vulnerability in admin/authenticate.asp in Battle Blog 1.25 and 1.30 build 2 allows remote attackers to execute arbitrary SQL commands via the UserName parameter.
|
CWE-89
SQL Injection
|
CVE-2009-3718
|
2017-09-19 10:29 |
2009-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257419
|
- |
|
davethewebguy
|
battle_blog
|
Cross-site scripting (XSS) vulnerability in comment.asp in Battle Blog 1.25 and 1.30 build 2 allows remote attackers to inject arbitrary web script or HTML via a comment.
|
CWE-79
Cross-site Scripting
|
CVE-2009-3719
|
2017-09-19 10:29 |
2009-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257420
|
- |
|
sun
|
jre
|
Unspecified vulnerability in the TrueType font parsing functionality in Sun Java SE 5.0 before Update 22 and 6 before Update 17 allows remote attackers to cause a denial of service (application crash…
|
NVD-CWE-noinfo
|
CVE-2009-3729
|
2017-09-19 10:29 |
2009-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|