256701
|
- |
|
elvinbts
|
elvinbts
|
Cross-site request forgery (CSRF) vulnerability in login.php in Elvin 1.2.0 allows remote attackers to hijack the authentication of arbitrary users via a logout action.
|
CWE-352
Origin Validation Error
|
CVE-2009-2129
|
2017-09-29 10:34 |
2009-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256702
|
- |
|
elvinbts
|
elvinbts
|
Elvin 1.2.0 allows remote attackers to read the PHP source code of (1) login.ei, (2) jump_bug.ei, or (3) create_account.ei in inc/ via a direct request.
|
CWE-200
Information Exposure
|
CVE-2009-2130
|
2017-09-29 10:34 |
2009-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256703
|
- |
|
4homepages
|
4images
|
Cross-site scripting (XSS) vulnerability in 4images 1.7.7 and earlier allows remote authenticated users to inject arbitrary web script or HTML by providing a crafted user_homepage parameter to member…
|
CWE-79
Cross-site Scripting
|
CVE-2009-2131
|
2017-09-29 10:34 |
2009-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256704
|
- |
|
sun
|
opensolaris solaris
|
Multiple race conditions in the Solaris Event Port API in Sun Solaris 10 and OpenSolaris before snv_107 allow local users to cause a denial of service (panic) via unspecified vectors related to a rac…
|
CWE-362
Race Condition
|
CVE-2009-2135
|
2017-09-29 10:34 |
2009-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256705
|
- |
|
tbdev
|
tbdev.net
|
Multiple open redirect vulnerabilities in TBDev.NET 01-01-08 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via (1) the returnto parameter to login.php o…
|
CWE-20
Improper Input Validation
|
CVE-2009-2138
|
2017-09-29 10:34 |
2009-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256706
|
- |
|
tbdev
|
tbdev.net
|
Multiple cross-site scripting (XSS) vulnerabilities in TBDev.NET 01-01-08 allow remote attackers to inject arbitrary web script or HTML via (1) the returnto parameter to makepoll.php, (2) the returnt…
|
CWE-79
Cross-site Scripting
|
CVE-2009-2141
|
2017-09-29 10:34 |
2009-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256707
|
- |
|
zipstore
|
zip_store_chat
|
Multiple SQL injection vulnerabilities in admin/index.asp in Zip Store Chat 4.0 and 5.0 allow remote attackers to execute arbitrary SQL commands via the (1) login and (2) senha parameters.
|
CWE-89
SQL Injection
|
CVE-2009-2142
|
2017-09-29 10:34 |
2009-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256708
|
- |
|
firestats
|
firestats
|
PHP remote file inclusion vulnerability in firestats-wordpress.php in the FireStats plugin before 1.6.2-stable for WordPress allows remote attackers to execute arbitrary PHP code via a URL in the fs_…
|
CWE-94
Code Injection
|
CVE-2009-2143
|
2017-09-29 10:34 |
2009-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256709
|
- |
|
pantha
|
translucid
|
Multiple cross-site scripting (XSS) vulnerabilities in transLucid 1.75 allow remote attackers to inject arbitrary web script or HTML via the (a) NodeID and (b) action parameters to the default URI, a…
|
CWE-79
Cross-site Scripting
|
CVE-2009-2145
|
2017-09-29 10:34 |
2009-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256710
|
- |
|
phpwebthings
|
phpwebthings
|
SQL injection vulnerability in fdown.php in phpWebThings 1.5.2 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2009-2147
|
2017-09-29 10:34 |
2009-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|