259051
|
- |
|
adsdx
|
adsdx
|
SQL injection vulnerability in admin/index.php in AdsDX 3.05 allows remote attackers to execute arbitrary SQL commands via the Username.
|
CWE-89
SQL Injection
|
CVE-2009-3667
|
2017-09-19 10:29 |
2009-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259052
|
- |
|
foobla
|
com_foobla_suggestions
|
SQL injection vulnerability in the foobla Suggestions (com_foobla_suggestions) component 1.5.11 for Joomla! allows remote attackers to execute arbitrary SQL commands via the idea_id parameter to inde…
|
CWE-89
SQL Injection
|
CVE-2009-3669
|
2017-09-19 10:29 |
2009-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259053
|
- |
|
ksplayer
|
ksp_sound_player
|
Stack-based buffer overflow in KSP Sound Player 2009 R2 and R2.1 allows remote attackers to execute arbitrary code via a long string in a .m3u playlist file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-3670
|
2017-09-19 10:29 |
2009-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259054
|
- |
|
ebayclonescript
|
ebay_clone
|
Multiple SQL injection vulnerabilities in Ebay Clone 2009 allow remote attackers to execute arbitrary SQL commands via the (1) user_id parameter to feedback.php; and the item_id parameter to (2) view…
|
CWE-89
SQL Injection
|
CVE-2009-3712
|
2017-09-19 10:29 |
2009-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259055
|
- |
|
morcego
|
morcegocms
|
SQL injection vulnerability in fichero.php in MorcegoCMS 1.7.6 and earlier allows remote attackers to execute arbitrary SQL commands via the query string.
|
CWE-89
SQL Injection
|
CVE-2009-3713
|
2017-09-19 10:29 |
2009-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259056
|
- |
|
maniacomputer
|
mcshoutbox
|
Cross-site scripting (XSS) vulnerability in admin_login.php in MCshoutbox 1.1 allows remote attackers to inject arbitrary web script or HTML via the loginerror parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2009-3714
|
2017-09-19 10:29 |
2009-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259057
|
- |
|
maniacomputer
|
mcshoutbox
|
Multiple SQL injection vulnerabilities in scr_login.php in MCshoutbox 1.1, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) pas…
|
CWE-89
SQL Injection
|
CVE-2009-3715
|
2017-09-19 10:29 |
2009-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259058
|
- |
|
maniacomputer
|
mcshoutbox
|
Unrestricted file upload vulnerability in admin.php in MCshoutbox 1.1 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it v…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-3716
|
2017-09-19 10:29 |
2009-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259059
|
- |
|
lucvil
|
patplayer
|
Heap-based buffer overflow in LucVil PatPlayer 3.9 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long URI in a playlist (.m3u) file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-3717
|
2017-09-19 10:29 |
2009-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259060
|
- |
|
davethewebguy
|
battle_blog
|
SQL injection vulnerability in admin/authenticate.asp in Battle Blog 1.25 and 1.30 build 2 allows remote attackers to execute arbitrary SQL commands via the UserName parameter.
|
CWE-89
SQL Injection
|
CVE-2009-3718
|
2017-09-19 10:29 |
2009-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|