258061
|
- |
|
sbuilder
|
cms_s.builder
|
PHP remote file inclusion vulnerability in index.php in CMS S.Builder 3.7 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in a binn_incl…
|
CWE-94
Code Injection
|
CVE-2009-4887
|
2017-09-19 10:30 |
2010-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258062
|
- |
|
basti2web
|
book_panel
|
SQL injection vulnerability in books.php in the Book Panel (book_panel) module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the bookid parameter.
|
CWE-89
SQL Injection
|
CVE-2009-4889
|
2017-09-19 10:30 |
2010-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258063
|
- |
|
cs-cart
|
cs-cart
|
SQL injection vulnerability in index.php in CS-Cart 2.0.0 Beta 3 allows remote attackers to execute arbitrary SQL commands via the product_id parameter in a products.view action.
|
CWE-89
SQL Injection
|
CVE-2009-4891
|
2017-09-19 10:30 |
2010-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258064
|
- |
|
webjump
|
webjump\!
|
SQL injection vulnerability in Content Management System WEBjump! allows remote attackers to execute arbitrary SQL commands via the id parameter to (1) portfolio_genre.php and (2) news_id.php.
|
CWE-89
SQL Injection
|
CVE-2009-4892
|
2017-09-19 10:30 |
2010-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258065
|
- |
|
david_degner
|
phpcollegeexchange
|
Multiple PHP remote file inclusion vulnerabilities in phpCollegeExchange 0.1.5c, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the home parameter…
|
CWE-94
Code Injection
|
CVE-2009-2218
|
2017-09-19 10:29 |
2009-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258066
|
- |
|
david_degner
|
phpcollegeexchange
|
Multiple cross-site scripting (XSS) vulnerabilities in phpCollegeExchange 0.1.5c allow remote attackers to inject arbitrary web script or HTML via the (1) _SESSION[handle] parameter to (a) home.php, …
|
CWE-79
Cross-site Scripting
|
CVE-2009-2219
|
2017-09-19 10:29 |
2009-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258067
|
- |
|
teozkr
|
lightopencms
|
Directory traversal vulnerability in locms/smarty.php in LightOpenCMS 0.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the cwd parameter. NOTE: remote f…
|
CWE-22
Path Traversal
|
CVE-2009-2223
|
2017-09-19 10:29 |
2009-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258068
|
- |
|
an_guestbook
|
an_guestbook
|
Directory traversal vulnerability in ang/shared/flags.php in AN Guestbook 0.7.8, when register_globals is enabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the g_lang par…
|
CWE-22
Path Traversal
|
CVE-2009-2224
|
2017-09-19 10:29 |
2009-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258069
|
- |
|
tribiq
|
tribiq_cms
|
Multiple directory traversal vulnerabilities in Tribiq CMS 5.0.12c, when register_globals is enabled and magic_quotes_gpc is disabled, allow remote attackers to include and possibly execute arbitrary…
|
CWE-22
Path Traversal
|
CVE-2009-2220
|
2017-09-19 10:29 |
2009-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258070
|
- |
|
blabsoft
|
bopup_communication_server
|
Stack-based buffer overflow in B Labs Bopup Communication Server 3.2.26.5460 allows remote attackers to execute arbitrary code via a crafted request to TCP port 19810.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-2227
|
2017-09-19 10:29 |
2009-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|