258461
|
- |
|
opial
|
opial
|
Cross-site scripting (XSS) vulnerability in home.php in Opial 1.0 allows remote attackers to inject arbitrary web script or HTML via the genres_parent parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2009-3751
|
2017-09-19 10:29 |
2009-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258462
|
- |
|
opial
|
opial
|
SQL injection vulnerability in home.php in Opial 1.0 allows remote attackers to execute arbitrary SQL commands via the genres_parent parameter.
|
CWE-89
SQL Injection
|
CVE-2009-3752
|
2017-09-19 10:29 |
2009-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258463
|
- |
|
opial
|
opial
|
Unrestricted file upload vulnerability in Opial 1.0 allows remote attackers to execute arbitrary code by uploading a file with an executable extension as a User Image, then accessing it via a request…
|
CWE-20
Improper Input Validation
|
CVE-2009-3753
|
2017-09-19 10:29 |
2009-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258464
|
- |
|
kreotek
|
phpbms
|
Multiple SQL injection vulnerabilities in phpBMS 0.96 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to modules/bms/invoices_discount_ajax.php, (2) f parameter to d…
|
CWE-89
SQL Injection
|
CVE-2009-3754
|
2017-09-19 10:29 |
2009-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258465
|
- |
|
kreotek
|
phpbms
|
Multiple cross-site scripting (XSS) vulnerabilities in phpBMS 0.96 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) index.php and (2) modules\base\myaccount.php;…
|
CWE-79
Cross-site Scripting
|
CVE-2009-3755
|
2017-09-19 10:29 |
2009-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258466
|
- |
|
kreotek
|
phpbms
|
phpBMS 0.96 allows remote attackers to obtain sensitive information via a direct request to (1) footer.php, (2) header.php, (3) the show action in advancedsearch.php, and (4) choicelist.php, which re…
|
CWE-200
Information Exposure
|
CVE-2009-3756
|
2017-09-19 10:29 |
2009-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258467
|
- |
|
citrix
|
xencenterweb
|
Multiple cross-site scripting (XSS) vulnerabilities in sample code in the XenServer Resource Kit in Citrix XenCenterWeb allow remote attackers to inject arbitrary web script or HTML via the (1) usern…
|
CWE-79
Cross-site Scripting
|
CVE-2009-3757
|
2017-09-19 10:29 |
2009-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258468
|
- |
|
citrix
|
xencenterweb
|
SQL injection vulnerability in login.php in sample code in the XenServer Resource Kit in Citrix XenCenterWeb allows remote attackers to execute arbitrary SQL commands via the username parameter. NOT…
|
CWE-89
SQL Injection
|
CVE-2009-3758
|
2017-09-19 10:29 |
2009-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258469
|
- |
|
citrix
|
xencenterweb
|
Static code injection vulnerability in config/writeconfig.php in the sample code in the XenServer Resource Kit in Citrix XenCenterWeb allows remote attackers to inject arbitrary PHP code into include…
|
CWE-94
Code Injection
|
CVE-2009-3760
|
2017-09-19 10:29 |
2009-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258470
|
- |
|
adobe
|
adobe_air flash_player
|
Adobe Flash Player 10.x before 10.0.42.34 and Adobe AIR before 1.5.3 might allow attackers to execute arbitrary code via unspecified vectors that trigger memory corruption.
|
CWE-399
Resource Management Errors
|
CVE-2009-3797
|
2017-09-19 10:29 |
2009-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|