|
291031
|
- |
|
agtc
|
agtc_myshop
|
AGTC MyShop 3.2b allows remote attackers to bypass authentication and obtain administrative access setting the log_accept cookie to "correcto."
|
CWE-287
Improper Authentication
|
CVE-2009-1549
|
2017-09-29 10:34 |
2009-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291032
|
- |
|
zakkis
|
abc_advertise
|
Zakkis Technology ABC Advertise 1.0 does not properly restrict access to admin.inc.php, which allows remote attackers to obtain the administrator login name and password via a direct request.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-1550
|
2017-09-29 10:34 |
2009-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291033
|
- |
|
qt-cute
|
quickteam
|
Multiple PHP remote file inclusion vulnerabilities in Qt quickteam 2 allow remote attackers to execute arbitrary PHP code via a URL in the (1) qte_web_path parameter to qte_web.php and the (2) qte_ro…
|
CWE-94
Code Injection
|
CVE-2009-1551
|
2017-09-29 10:34 |
2009-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291034
|
- |
|
ipsec-tools
|
ipsec-tools
|
racoon/isakmp_frag.c in ipsec-tools before 0.7.2 allows remote attackers to cause a denial of service (crash) via crafted fragmented packets without a payload, which triggers a NULL pointer dereferen…
|
NVD-CWE-Other
|
CVE-2009-1574
|
2017-09-29 10:34 |
2009-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291035
|
- |
|
cscope
|
cscope
|
Multiple stack-based buffer overflows in the putstring function in find.c in Cscope before 15.6 allow user-assisted remote attackers to execute arbitrary code via a long (1) function name or (2) symb…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-1577
|
2017-09-29 10:34 |
2009-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291036
|
- |
|
squirrelmail
|
squirrelmail
|
Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail before 1.4.18 and NaSMail before 1.7 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) certai…
|
CWE-79
Cross-site Scripting
|
CVE-2009-1578
|
2017-09-29 10:34 |
2009-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291037
|
- |
|
squirrelmail
|
squirrelmail
|
The map_yp_alias function in functions/imap_general.php in SquirrelMail before 1.4.18 and NaSMail before 1.7 allows remote attackers to execute arbitrary commands via shell metacharacters in a userna…
|
CWE-94
Code Injection
|
CVE-2009-1579
|
2017-09-29 10:34 |
2009-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291038
|
- |
|
squirrelmail
|
squirrelmail
|
Session fixation vulnerability in SquirrelMail before 1.4.18 allows remote attackers to hijack web sessions via a crafted cookie.
|
CWE-287
Improper Authentication
|
CVE-2009-1580
|
2017-09-29 10:34 |
2009-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291039
|
- |
|
squirrelmail
|
squirrelmail
|
functions/mime.php in SquirrelMail before 1.4.18 does not protect the application's content from Cascading Style Sheets (CSS) positioning in HTML e-mail messages, which allows remote attackers to spo…
|
CWE-79
Cross-site Scripting
|
CVE-2009-1581
|
2017-09-29 10:34 |
2009-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291040
|
- |
|
kalptarudemos
|
million_dollar_text_links
|
Million Dollar Text Links 1.0 does not properly restrict administrator access to admin.home.php, which allows remote attackers to bypass intended restrictions and gain privileges via a direct request…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-1582
|
2017-09-29 10:34 |
2009-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|