260971
|
- |
|
plunet
|
business_manager
|
Plunet BusinessManager 4.1 and earlier allows remote authenticated users to bypass access restrictions and (1) read sensitive Customer or Order data via a modified Pfad parameter to pagesUTF8/Sys_Dir…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-0700
|
2017-08-17 10:29 |
2009-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260972
|
- |
|
simple-review
|
com_simple_review
|
SQL injection vulnerability in the Simple Review (com_simple_review) component 1.3.5 for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the category parameter to inde…
|
CWE-89
SQL Injection
|
CVE-2009-0706
|
2017-08-17 10:29 |
2009-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260973
|
- |
|
vlad_alexa_mancini
|
phpfootball
|
SQL injection vulnerability in login.php in PHPFootball 1.6 allows remote attackers to execute arbitrary SQL commands via the user parameter. NOTE: the provenance of this information is unknown; the…
|
CWE-89
SQL Injection
|
CVE-2009-0709
|
2017-08-17 10:29 |
2009-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260974
|
- |
|
vlad_alexa_mancini
|
phpfootball
|
Multiple cross-site scripting (XSS) vulnerabilities in PHPFootball 1.6 allow remote attackers to inject arbitrary web script or HTML via (1) the user parameter to login.php or (2) the dbfield paramet…
|
CWE-79
Cross-site Scripting
|
CVE-2009-0710
|
2017-08-17 10:29 |
2009-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260975
|
- |
|
lingx
|
page_engine_cms
|
Multiple directory traversal vulnerabilities in Page Engine CMS 2.0 Basic and Pro allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the fPrefix …
|
CWE-22
Path Traversal
|
CVE-2009-0729
|
2017-08-17 10:29 |
2009-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260976
|
- |
|
mozilo
|
mozilocms
|
Multiple directory traversal vulnerabilities in moziloCMS 1.10.2 and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) file parameter to download.php and the (2) pa…
|
CWE-22
Path Traversal
|
CVE-2008-6126
|
2017-08-17 10:29 |
2009-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260977
|
- |
|
mozilo
|
mozilocms
|
Multiple cross-site scripting (XSS) vulnerabilities in moziloCMS 1.10.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) page and (2) query parameters to (a) inde…
|
CWE-79
Cross-site Scripting
|
CVE-2008-6127
|
2017-08-17 10:29 |
2009-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260978
|
- |
|
mozilo
|
mozilocms
|
Session fixation vulnerability in moziloCMS 1.10.2 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.
|
CWE-287
Improper Authentication
|
CVE-2008-6128
|
2017-08-17 10:29 |
2009-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260979
|
- |
|
mozilo
|
mozilowiki
|
Directory traversal vulnerability in print.php in moziloWiki 1.0.1 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter.
|
CWE-22
Path Traversal
|
CVE-2008-6129
|
2017-08-17 10:29 |
2009-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260980
|
- |
|
mozilo
|
mozilowiki
|
Cross-site scripting (XSS) vulnerability in index.php in moziloWiki 1.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) action and (2) page parameters.
|
CWE-79
Cross-site Scripting
|
CVE-2008-6130
|
2017-08-17 10:29 |
2009-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|