258411
|
- |
|
fcgphilipp
|
mujecms
|
Multiple directory traversal vulnerabilities in MUJE CMS 1.0.4.34 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) _class parameter to admin.php and t…
|
CWE-22
Path Traversal
|
CVE-2009-3508
|
2017-09-19 10:29 |
2009-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258412
|
- |
|
dataspheric
|
linkspheric
|
SQL injection vulnerability in viewListing.php in linkSpheric 0.74 Beta 6 allows remote attackers to execute arbitrary SQL commands via the listID parameter.
|
CWE-89
SQL Injection
|
CVE-2009-3510
|
2017-09-19 10:29 |
2009-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258413
|
- |
|
fh54
|
justvisual
|
Multiple PHP remote file inclusion vulnerabilities in justVisual 1.2 allow remote attackers to execute arbitrary PHP code via a URL in the fs_jVroot parameter to (1) sites/site/pages/index.php, (2) s…
|
CWE-94
Code Injection
|
CVE-2009-3511
|
2017-09-19 10:29 |
2009-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258414
|
- |
|
marcin_manek
|
d.net_cms
|
Multiple SQL injection vulnerabilities in d.net CMS allow remote attackers to execute arbitrary SQL commands via (1) the page parameter to index.php; and allow remote authenticated administrators to …
|
CWE-89
SQL Injection
|
CVE-2009-3514
|
2017-09-19 10:29 |
2009-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258415
|
- |
|
marcin_manek
|
d.net_cms
|
Directory traversal vulnerability in dnet_admin/index.php in d.net CMS allows remote authenticated administrators to include and execute arbitrary local files via a .. (dot dot) in the type parameter.
|
CWE-22
Path Traversal
|
CVE-2009-3515
|
2017-09-19 10:29 |
2009-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258416
|
- |
|
ibm
|
aix
|
gssd in IBM AIX 5.3.x through 5.3.9 and 6.1.0 through 6.1.2 does not properly handle the NFSv4 Kerberos credential cache, which allows local users to bypass intended access restrictions for Kerberize…
|
CWE-255
Credentials Management
|
CVE-2009-3516
|
2017-09-19 10:29 |
2009-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258417
|
- |
|
ibm
|
aix
|
nfs.ext in IBM AIX 5.3.x through 5.3.9 and 6.1.0 through 6.1.2 does not properly use the nfs_portmon setting, which allows remote attackers to bypass intended access restrictions for NFSv4 shares via…
|
NVD-CWE-noinfo
|
CVE-2009-3517
|
2017-09-19 10:29 |
2009-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258418
|
- |
|
avast
|
avast_antivirus_home avast_antivirus_professional
|
aavmKer4.sys in avast! Home and Professional for Windows before 4.8.1356 does not properly validate input to IOCTLs (1) 0xb2d6000c and (2) 0xb2d60034, which allows local users to gain privileges via …
|
CWE-20
Improper Input Validation
|
CVE-2009-3523
|
2017-09-19 10:29 |
2009-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258419
|
- |
|
avast
|
avast_antivirus_home avast_antivirus_professional
|
Unspecified vulnerability in ashWsFtr.dll in avast! Home and Professional for Windows before 4.8.1356 has unknown impact and local attack vectors.
|
NVD-CWE-noinfo
|
CVE-2009-3524
|
2017-09-19 10:29 |
2009-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258420
|
- |
|
xen
|
xen
|
The pyGrub boot loader in Xen 3.0.3, 3.3.0, and Xen-3.3.1 does not support the password option in grub.conf for para-virtualized guests, which allows attackers with access to the para-virtualized gue…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-3525
|
2017-09-19 10:29 |
2009-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|