258821
|
- |
|
uwix
|
com_digifolio
|
SQL injection vulnerability in the DigiFolio (com_digifolio) component 1.52 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a project action to index.php.
|
CWE-89
SQL Injection
|
CVE-2009-3193
|
2017-09-19 10:29 |
2009-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258822
|
- |
|
uebimiau
|
uebimiau
|
Uebimiau Webmail 3.2.0-2.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database with usernames and password hashes vi…
|
CWE-200
Information Exposure
|
CVE-2009-3199
|
2017-09-19 10:29 |
2009-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258823
|
- |
|
rob_schultz
|
media_player_classic
|
Integer overflow in Media Player Classic 6.4.9 allows user-assisted remote attackers to cause a denial of service (application crash) via a MIDI file (.mid) with a malformed header, which triggers a …
|
CWE-189
Numeric Errors
|
CVE-2009-3201
|
2017-09-19 10:29 |
2009-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258824
|
- |
|
wiccle
|
iwiccle
|
Multiple directory traversal vulnerabilities in iWiccle 1.01, when magic_quotes_gpc is disabled, allow remote attackers to read arbitrary files via a .. (dot dot) in (1) the show parameter to the adm…
|
CWE-22
Path Traversal
|
CVE-2009-3216
|
2017-09-19 10:29 |
2009-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258825
|
- |
|
wiccle
|
iwiccle
|
SQL injection vulnerability in the admin module in iWiccle 1.01 allows remote attackers to execute arbitrary SQL commands via the member_id parameter in an edit_user action to index.php.
|
CWE-89
SQL Injection
|
CVE-2009-3217
|
2017-09-19 10:29 |
2009-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258826
|
- |
|
the-ghost
|
ar_web_content_manager
|
SQL injection vulnerability in control/login.php in AR Web Content Manager (AWCM) 2.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the username pa…
|
CWE-89
SQL Injection
|
CVE-2009-3218
|
2017-09-19 10:29 |
2009-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258827
|
- |
|
the-ghost
|
ar_web_content_manager
|
Directory traversal vulnerability in a.php in AR Web Content Manager (AWCM) 2.1, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot …
|
CWE-22
Path Traversal
|
CVE-2009-3219
|
2017-09-19 10:29 |
2009-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258828
|
- |
|
inoutscripts
|
inout_adserver
|
SQL injection vulnerability in ppc-add-keywords.php in Inout Adserver allows remote authenticated users to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2009-3223
|
2017-09-19 10:29 |
2009-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258829
|
- |
|
classified-software
|
super_mod_system
|
SQL injection vulnerability in index.php in Super Mod System, when using the 68 Classifieds 3.1 Core System, allows remote attackers to execute arbitrary SQL commands via the s parameter.
|
CWE-89
SQL Injection
|
CVE-2009-3224
|
2017-09-19 10:29 |
2009-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258830
|
- |
|
dovecot
|
dovecot
|
Multiple stack-based buffer overflows in the Sieve plugin in Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, as derived from Cyrus libsieve, allow context-dependent attackers to cause a denial of serv…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-3235
|
2017-09-19 10:29 |
2009-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|