|
291171
|
- |
|
newsboard
|
unclassified_newsboard
|
SQL injection vulnerability in the UnbDbEncode function in unb_lib/database.lib.php in Unclassified NewsBoard (UNB) 1.6.4 allows remote attackers to execute arbitrary SQL commands via the Query param…
|
CWE-89
SQL Injection
|
CVE-2009-1947
|
2017-09-29 10:34 |
2009-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291172
|
- |
|
unclassified
|
newsboard
|
Multiple directory traversal vulnerabilities in forum.php in Unclassified NewsBoard (UNB) 1.6.4, when register_globals is enabled and magic_quotes_gpc is disabled, allow remote attackers to (1) read …
|
CWE-22
Path Traversal
|
CVE-2009-1948
|
2017-09-29 10:34 |
2009-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291173
|
- |
|
unclassified
|
newsboard
|
import_wbb1.php in Unclassified NewsBoard (UNB) 1.6.4 allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message.
|
CWE-200
Information Exposure
|
CVE-2009-1949
|
2017-09-29 10:34 |
2009-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291174
|
- |
|
ahmet_donmez
|
webeyes_guest_book
|
SQL injection vulnerability in yorum.asp in WebEyes Guest Book 3 allows remote attackers to execute arbitrary SQL commands via the mesajid parameter.
|
CWE-89
SQL Injection
|
CVE-2009-1950
|
2017-09-29 10:34 |
2009-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291175
|
- |
|
propertymaxpro
|
propertymax_pro_free
|
Cross-site scripting (XSS) vulnerability in index.php in PropertyMax Pro FREE 0.3 allows remote attackers to inject arbitrary web script or HTML via the pl parameter in a mi action.
|
CWE-79
Cross-site Scripting
|
CVE-2009-1951
|
2017-09-29 10:34 |
2009-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291176
|
- |
|
propertymaxpro
|
propertymax_pro_free
|
Multiple SQL injection vulnerabilities in the administrative login feature in PropertyMax Pro FREE 0.3, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via…
|
CWE-89
SQL Injection
|
CVE-2009-1952
|
2017-09-29 10:34 |
2009-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291177
|
- |
|
ascadnetworks
|
password_protector_sd
|
Ascad Networks Password Protector SD 1.3.1 allows remote attackers to bypass authentication and gain administrative access by setting the (1) c7portal and (2) cookname cookies to "admin."
|
CWE-287
Improper Authentication
|
CVE-2009-2003
|
2017-09-29 10:34 |
2009-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291178
|
- |
|
frontisgroup
|
frontis
|
SQL injection vulnerability in bin/aps_browse_sources.php in Frontis 3.9.01.24 allows remote attackers to execute arbitrary SQL commands via the source_class parameter in a browse_classes action.
|
CWE-89
SQL Injection
|
CVE-2009-2013
|
2017-09-29 10:34 |
2009-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291179
|
- |
|
joomla
|
com_school
|
SQL injection vulnerability in the ComSchool (com_school) component 1.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the classid parameter in a showclass action to index.…
|
CWE-89
SQL Injection
|
CVE-2009-2014
|
2017-09-29 10:34 |
2009-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291180
|
- |
|
ideal
|
com_moofaq
|
Directory traversal vulnerability in includes/file_includer.php in the Ideal MooFAQ (com_moofaq) component 1.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the fi…
|
CWE-22
Path Traversal
|
CVE-2009-2015
|
2017-09-29 10:34 |
2009-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|