|
291181
|
- |
|
virtuenetz
|
virtue_shopping_mall
|
SQL injection vulnerability in products.php in Virtue Shopping Mall allows remote attackers to execute arbitrary SQL commands via the cid parameter.
|
CWE-89
SQL Injection
|
CVE-2009-2016
|
2017-09-29 10:34 |
2009-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291182
|
- |
|
virtuenetz
|
virtue_book_store
|
SQL injection vulnerability in products.php in Virtue Book Store allows remote attackers to execute arbitrary SQL commands via the cid parameter.
|
CWE-89
SQL Injection
|
CVE-2009-2017
|
2017-09-29 10:34 |
2009-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291183
|
- |
|
jaredeckersley
|
mycars
|
SQL injection vulnerability in admin/index.php in Jared Eckersley MyCars, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the authuserid parameter.
|
CWE-89
SQL Injection
|
CVE-2009-2018
|
2017-09-29 10:34 |
2009-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291184
|
- |
|
virtuenetz
|
virtue_news_manager
|
SQL injection vulnerability in news_detail.php in Virtue News Manager allows remote attackers to execute arbitrary SQL commands via the nid parameter.
|
CWE-89
SQL Injection
|
CVE-2009-2019
|
2017-09-29 10:34 |
2009-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291185
|
- |
|
virtuenetz
|
virtue_news_manager
|
Cross-site scripting (XSS) vulnerability in news_detail.php in Virtue News Manager allows remote attackers to inject arbitrary web script or HTML via the nid parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2009-2020
|
2017-09-29 10:34 |
2009-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291186
|
- |
|
virtuenetz
|
virtue_classifieds
|
SQL injection vulnerability in search.php in Virtue Classifieds allows remote attackers to execute arbitrary SQL commands via the category parameter.
|
CWE-89
SQL Injection
|
CVE-2009-2021
|
2017-09-29 10:34 |
2009-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291187
|
- |
|
fipsasp
|
fipscms_light
|
fipsCMS Light 2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file and obtain sensitive information via a …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-2022
|
2017-09-29 10:34 |
2009-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291188
|
- |
|
shop-script
|
shop-script
|
SQL injection vulnerability in index.php in Shop-Script Pro 2.12, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the current_currency parameter.
|
CWE-89
SQL Injection
|
CVE-2009-2023
|
2017-09-29 10:34 |
2009-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291189
|
- |
|
vt.rovno
|
asp_vt_auth
|
Vlad Titarenko ASP VT Auth 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file and obtain usernames and p…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-2024
|
2017-09-29 10:34 |
2009-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291190
|
- |
|
dutchmonkey
|
dm_filemanager
|
admin/login.php in DM FileManager 3.9.2 allows remote attackers to bypass authentication and gain administrative access by setting the (1) USER, (2) GROUPID, (3) GROUP, and (4) USERID cookies to cert…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-2025
|
2017-09-29 10:34 |
2009-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|