258501
|
- |
|
tutorial-share
|
tutorial_share
|
Optimum Web Design Tutorial Share 3.5.0 and earlier allows remote attackers to bypass authentication and obtain administrative access by setting the usernamed cookie parameter.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-2293
|
2017-09-19 10:29 |
2009-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258502
|
- |
|
armassa
|
ard-9808_software ard-9808
|
The ARD-9808 DVR card security camera allows remote attackers to cause a denial of service via a long URI composed of //.\ (slash slash dot backslash) sequences.
|
CWE-20
Improper Input Validation
|
CVE-2009-2305
|
2017-09-19 10:29 |
2009-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258503
|
- |
|
armassa
|
ard-9808_software ard-9808
|
The ARD-9808 DVR card security camera stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a file containing usernames and passw…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-2306
|
2017-09-19 10:29 |
2009-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258504
|
- |
|
maxdev
|
cwguestbook
|
SQL injection vulnerability in the CWGuestBook module 2.1 and earlier for MAXdev MDPro (aka MD-Pro) allows remote attackers to execute arbitrary SQL commands via the rid parameter in a viewrecords ac…
|
CWE-89
SQL Injection
|
CVE-2009-2307
|
2017-09-19 10:29 |
2009-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258505
|
- |
|
punres
|
affiliates_mod
|
Multiple SQL injection vulnerabilities in affiliates.php in the Affiliation (aka Affiliates) module 1.1.0 and earlier for PunBB allow remote attackers to execute arbitrary SQL commands via the (1) in…
|
CWE-89
SQL Injection
|
CVE-2009-2308
|
2017-09-19 10:29 |
2009-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258506
|
- |
|
codice-cms
|
codice_cms
|
SQL injection vulnerability in index.php in Codice CMS 2 allows remote attackers to execute arbitrary SQL commands via the tag parameter.
|
CWE-89
SQL Injection
|
CVE-2009-2309
|
2017-09-19 10:29 |
2009-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258507
|
- |
|
bow_der_kleine
|
x-blc
|
SQL injection vulnerability in include/get_read.php in Extensible-BioLawCom CMS (X-BLC) 0.2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the section parameter.
|
CWE-89
SQL Injection
|
CVE-2009-2310
|
2017-09-19 10:29 |
2009-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258508
|
- |
|
selbstzweck
|
rgallery_plugin
|
SQL injection vulnerability in the rGallery plugin 1.2.3 for WoltLab Burning Board (WBB3) allows remote attackers to execute arbitrary SQL commands via the userID parameter in the RGalleryUserGallery…
|
CWE-89
SQL Injection
|
CVE-2009-2311
|
2017-09-19 10:29 |
2009-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258509
|
- |
|
jinzora
|
jinzora
|
Directory traversal vulnerability in index.php in Jinzora Media Jukebox 2.8 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the name parameter.
|
CWE-22
Path Traversal
|
CVE-2009-2313
|
2017-09-19 10:29 |
2009-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258510
|
- |
|
clicknet
|
clicknet_cms
|
Directory traversal vulnerability in index.php in Clicknet CMS 2.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the side parameter.
|
CWE-22
Path Traversal
|
CVE-2009-2325
|
2017-09-19 10:29 |
2009-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|