258451
|
- |
|
maniacomputer
|
mcshoutbox
|
Cross-site scripting (XSS) vulnerability in admin_login.php in MCshoutbox 1.1 allows remote attackers to inject arbitrary web script or HTML via the loginerror parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2009-3714
|
2017-09-19 10:29 |
2009-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258452
|
- |
|
maniacomputer
|
mcshoutbox
|
Multiple SQL injection vulnerabilities in scr_login.php in MCshoutbox 1.1, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) pas…
|
CWE-89
SQL Injection
|
CVE-2009-3715
|
2017-09-19 10:29 |
2009-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258453
|
- |
|
maniacomputer
|
mcshoutbox
|
Unrestricted file upload vulnerability in admin.php in MCshoutbox 1.1 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it v…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-3716
|
2017-09-19 10:29 |
2009-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258454
|
- |
|
lucvil
|
patplayer
|
Heap-based buffer overflow in LucVil PatPlayer 3.9 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long URI in a playlist (.m3u) file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-3717
|
2017-09-19 10:29 |
2009-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258455
|
- |
|
davethewebguy
|
battle_blog
|
SQL injection vulnerability in admin/authenticate.asp in Battle Blog 1.25 and 1.30 build 2 allows remote attackers to execute arbitrary SQL commands via the UserName parameter.
|
CWE-89
SQL Injection
|
CVE-2009-3718
|
2017-09-19 10:29 |
2009-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258456
|
- |
|
davethewebguy
|
battle_blog
|
Cross-site scripting (XSS) vulnerability in comment.asp in Battle Blog 1.25 and 1.30 build 2 allows remote attackers to inject arbitrary web script or HTML via a comment.
|
CWE-79
Cross-site Scripting
|
CVE-2009-3719
|
2017-09-19 10:29 |
2009-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258457
|
- |
|
sun
|
jre
|
Unspecified vulnerability in the TrueType font parsing functionality in Sun Java SE 5.0 before Update 22 and 6 before Update 17 allows remote attackers to cause a denial of service (application crash…
|
NVD-CWE-noinfo
|
CVE-2009-3729
|
2017-09-19 10:29 |
2009-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258458
|
- |
|
gnu
|
libtool
|
ltdl.c in libltdl in GNU Libtool 1.5.x, and 2.2.6 before 2.2.6b, as used in Ham Radio Control Libraries, Q, and possibly other products, attempts to open a .la file in the current working directory, …
|
NVD-CWE-Other
|
CVE-2009-3736
|
2017-09-19 10:29 |
2009-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258459
|
- |
|
sun
|
solaris
|
XScreenSaver in Sun Solaris 10, when the accessibility feature is enabled, allows physically proximate attackers to obtain sensitive information by reading popup windows, which are displayed even whe…
|
CWE-16
Configuration
|
CVE-2009-3746
|
2017-09-19 10:29 |
2009-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258460
|
- |
|
santostefano_giovanni
|
toylog
|
SQL injection vulnerability in read.php in ToyLog 0.1 allows remote attackers to execute arbitrary SQL commands via the idm parameter.
|
CWE-89
SQL Injection
|
CVE-2009-3750
|
2017-09-19 10:29 |
2009-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|