258951
|
- |
|
saphplesson
|
saphplesson
|
SQL injection vulnerability in SaphpLesson 4.3, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the CLIENT_IP HTTP header.
|
CWE-89
SQL Injection
|
CVE-2009-3321
|
2017-09-19 10:29 |
2009-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258952
|
- |
|
robig
|
barosmini
|
Multiple PHP remote file inclusion vulnerabilities in BAnner ROtation System mini (BAROSmini) 0.32.595 allow remote attackers to execute arbitrary PHP code via a URL in the baros_path parameter to (1…
|
CWE-94
Code Injection
|
CVE-2009-3323
|
2017-09-19 10:29 |
2009-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258953
|
- |
|
andres_g_aragoneses
|
prodler
|
PHP remote file inclusion vulnerability in include/prodler.class.php in ProdLer 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the sPath parameter.
|
CWE-94
Code Injection
|
CVE-2009-3324
|
2017-09-19 10:29 |
2009-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258954
|
- |
|
focusdev
|
com_surveymanager
|
SQL injection vulnerability in the Focusplus Developments Survey Manager (com_surveymanager) component 1.5.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the stype parame…
|
CWE-89
SQL Injection
|
CVE-2009-3325
|
2017-09-19 10:29 |
2009-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258955
|
- |
|
cmscontrol
|
cmscontrol
|
SQL injection vulnerability in index.php in CMScontrol Content Management System 7.x allows remote attackers to execute arbitrary SQL commands via the id_menu parameter.
|
CWE-89
SQL Injection
|
CVE-2009-3326
|
2017-09-19 10:29 |
2009-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258956
|
- |
|
webilix
|
wx-guestbook
|
Multiple SQL injection vulnerabilities in WX-Guestbook 1.1.208 allow remote attackers to execute arbitrary SQL commands via the (1) QUERY parameter to search.php and (2) USERNAME parameter to login.p…
|
CWE-89
SQL Injection
|
CVE-2009-3327
|
2017-09-19 10:29 |
2009-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258957
|
- |
|
webilix
|
wx-guestbook
|
Cross-site scripting (XSS) vulnerability in sign.php in WX-Guestbook 1.1.208 allows remote attackers to inject arbitrary web script or HTML via the sName parameter (aka the name field). NOTE: some o…
|
CWE-79
Cross-site Scripting
|
CVE-2009-3328
|
2017-09-19 10:29 |
2009-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258958
|
- |
|
exeter
|
winplot
|
Stack-based buffer overflow in Winplot 1.25.0.1 allows user-assisted remote attackers to execute arbitrary code via a crafted Plot2D (.wp2) file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-3329
|
2017-09-19 10:29 |
2009-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258959
|
- |
|
cpecreator
|
cp_creator
|
SQL injection vulnerability in index.php in cP Creator 2.7.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the tickets parameter in a support ticke…
|
CWE-89
SQL Injection
|
CVE-2009-3330
|
2017-09-19 10:29 |
2009-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258960
|
- |
|
ddlcms
|
ddl_cms
|
Multiple PHP remote file inclusion vulnerabilities in DDL CMS 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the wwwRoot parameter to (1) header.php, (2) submit.php, (3) submit…
|
CWE-94
Code Injection
|
CVE-2009-3331
|
2017-09-19 10:29 |
2009-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|