257001
|
- |
|
matteoiammarrone
|
s-cms
|
SQL injection vulnerability in admin/delete_page.php in S-Cms 1.1 Stable allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2009-0863
|
2017-09-29 10:34 |
2009-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257002
|
- |
|
matteoiammarrone
|
s-cms
|
S-Cms 1.1 Stable allows remote attackers to bypass authentication and obtain administrative access via an OK value for the login cookie.
|
CWE-287
Improper Authentication
|
CVE-2009-0864
|
2017-09-29 10:34 |
2009-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257003
|
- |
|
phnews
|
phnews
|
pHNews Alpha 1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for extra/genbackup.php.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-0866
|
2017-09-29 10:34 |
2009-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257004
|
- |
|
josema_enzo
|
isiajax
|
SQL injection vulnerability in ejemplo/paises.php in isiAJAX 1 allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2009-0881
|
2017-09-29 10:34 |
2009-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257005
|
- |
|
amunak
|
blue_eye_cms
|
SQL injection vulnerability in Blue Eye CMS 1.0.0 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the BlueEyeCMS_login cookie parameter.
|
CWE-89
SQL Injection
|
CVE-2009-0883
|
2017-09-29 10:34 |
2009-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257006
|
- |
|
mediacommands
|
media_commands
|
Multiple heap-based buffer overflows in Media Commands 1.0 allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a long string in a (1) M3U, (2) M3l, (…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-0885
|
2017-09-29 10:34 |
2009-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257007
|
- |
|
oneorzero
|
oneorzero_helpdesk
|
Directory traversal vulnerability in login.php in OneOrZero Helpdesk 1.6.5.7 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the default_language parameter.
|
CWE-22
Path Traversal
|
CVE-2009-0886
|
2017-09-29 10:34 |
2009-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257008
|
- |
|
vmware
|
ace
|
Unspecified vulnerability in the ACE shared folders implementation in the VMware Host Guest File System (HGFS) shared folders feature in VMware ACE 2.5.1 and earlier allows attackers to enable a disa…
|
NVD-CWE-noinfo
|
CVE-2009-0908
|
2017-09-29 10:34 |
2009-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257009
|
- |
|
vmware
|
ace player server workstation
|
Heap-based buffer overflow in the VNnc Codec in VMware Workstation 6.5.x before 6.5.2 build 156735, VMware Player 2.5.x before 2.5.2 build 156735, VMware ACE 2.5.x before 2.5.2 build 156735, and VMwa…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-0909
|
2017-09-29 10:34 |
2009-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257010
|
- |
|
vmware
|
ace player server workstation
|
Heap-based buffer overflow in the VNnc Codec in VMware Workstation 6.5.x before 6.5.2 build 156735, VMware Player 2.5.x before 2.5.2 build 156735, VMware ACE 2.5.x before 2.5.2 build 156735, and VMwa…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-0910
|
2017-09-29 10:34 |
2009-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|