260671
|
- |
|
foswiki
|
foswiki
|
Cross-site request forgery (CSRF) vulnerability in Foswiki before 1.0.5 allows remote attackers to hijack the authentication of arbitrary users for requests that modify pages, change permissions, or …
|
CWE-352
Origin Validation Error
|
CVE-2009-1434
|
2017-08-17 10:30 |
2009-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260672
|
- |
|
amule
|
amule
|
Incomplete blacklist vulnerability in DownloadListCtrl.cpp in amule 2.2.4 allows remote attackers to conduct argument injection attacks into a command for mplayer via a crafted filename.
|
NVD-CWE-Other
|
CVE-2009-1440
|
2017-08-17 10:30 |
2009-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260673
|
- |
|
google
|
chrome
|
Heap-based buffer overflow in the ParamTraits<SkBitmap>::Read function in Google Chrome before 1.0.154.64 allows attackers to leverage renderer access to cause a denial of service (application crash)…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-1441
|
2017-08-17 10:30 |
2009-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260674
|
- |
|
lovpop
|
apricot
|
Cross-site scripting (XSS) vulnerability in apricot.php in LovPop.net APRICOT, probably 1.20, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.
|
CWE-79
Cross-site Scripting
|
CVE-2009-1448
|
2017-08-17 10:30 |
2009-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260675
|
- |
|
andrew_simpson
|
webcollab
|
Cross-site scripting (XSS) vulnerability in tasks.php in WebCollab before 2.50 (aka Billy Goat) allows remote attackers to inject arbitrary web script or HTML via the selection parameter in a todo ac…
|
CWE-79
Cross-site Scripting
|
CVE-2009-1454
|
2017-08-17 10:30 |
2009-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260676
|
- |
|
andrew_simpson
|
webcollab
|
Multiple cross-site request forgery (CSRF) vulnerabilities in WebCollab before 2.50 (aka Billy Goat) allow remote attackers to hijack the authentication of administrators for requests that change an …
|
CWE-352
Origin Validation Error
|
CVE-2009-1455
|
2017-08-17 10:30 |
2009-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260677
|
- |
|
evolution-extreme
|
nuke_evolution_xtreme
|
Cross-site scripting (XSS) vulnerability in player.php in Nuke Evolution Xtreme 2.x allows remote attackers to inject arbitrary web script or HTML via the defaultVisualExt parameter. NOTE: the prove…
|
CWE-79
Cross-site Scripting
|
CVE-2009-1457
|
2017-08-17 10:30 |
2009-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260678
|
- |
|
razorcms
|
razorcms
|
Multiple cross-site scripting (XSS) vulnerabilities in admin/index.php in razorCMS before 0.4 allow remote attackers to inject arbitrary web script or HTML via (1) the slab parameter in an edit actio…
|
CWE-79
Cross-site Scripting
|
CVE-2009-1458
|
2017-08-17 10:30 |
2009-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260679
|
- |
|
razorcms
|
razorcms
|
Cross-site request forgery (CSRF) vulnerability in razorCMS before 0.4 allows remote attackers to hijack the authentication of administrators for requests that create a web page containing PHP code.
|
CWE-352
Origin Validation Error
|
CVE-2009-1459
|
2017-08-17 10:30 |
2009-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260680
|
- |
|
razorcms
|
razorcms
|
razorCMS before 0.4 uses weak permissions for (1) admin/core/admin_config.php, which allows local users to obtain the administrator's password hash and FTP user credentials; and (2) the root director…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-1460
|
2017-08-17 10:30 |
2009-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|