|
291211
|
- |
|
paolo_palmonari
|
photoracer_plugin_for_wordpress
|
SQL injection vulnerability in viewimg.php in the Paolo Palmonari Photoracer plugin 1.0 for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2009-2122
|
2017-09-29 10:34 |
2009-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291212
|
- |
|
elvinbts
|
elvinbts
|
Multiple SQL injection vulnerabilities in Elvin 1.2.0 allow remote attackers to execute arbitrary SQL commands via the (1) inUser (aka Username) and (2) inPass (aka Password) parameters to (a) inc/lo…
|
CWE-89
SQL Injection
|
CVE-2009-2123
|
2017-09-29 10:34 |
2009-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291213
|
- |
|
elvinbts
|
elvinbts
|
Directory traversal vulnerability in page.php in Elvin 1.2.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the id parameter.
|
CWE-22
Path Traversal
|
CVE-2009-2124
|
2017-09-29 10:34 |
2009-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291214
|
- |
|
elvinbts
|
elvinbts
|
Cross-site scripting (XSS) vulnerability in show_activity.php in Elvin 1.2.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2009-2127
|
2017-09-29 10:34 |
2009-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291215
|
- |
|
elvinbts
|
elvinbts
|
Cross-site request forgery (CSRF) vulnerability in login.php in Elvin 1.2.0 allows remote attackers to hijack the authentication of arbitrary users via a logout action.
|
CWE-352
Origin Validation Error
|
CVE-2009-2129
|
2017-09-29 10:34 |
2009-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291216
|
- |
|
elvinbts
|
elvinbts
|
Elvin 1.2.0 allows remote attackers to read the PHP source code of (1) login.ei, (2) jump_bug.ei, or (3) create_account.ei in inc/ via a direct request.
|
CWE-200
Information Exposure
|
CVE-2009-2130
|
2017-09-29 10:34 |
2009-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291217
|
- |
|
4homepages
|
4images
|
Cross-site scripting (XSS) vulnerability in 4images 1.7.7 and earlier allows remote authenticated users to inject arbitrary web script or HTML by providing a crafted user_homepage parameter to member…
|
CWE-79
Cross-site Scripting
|
CVE-2009-2131
|
2017-09-29 10:34 |
2009-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291218
|
- |
|
sun
|
opensolaris solaris
|
Multiple race conditions in the Solaris Event Port API in Sun Solaris 10 and OpenSolaris before snv_107 allow local users to cause a denial of service (panic) via unspecified vectors related to a rac…
|
CWE-362
Race Condition
|
CVE-2009-2135
|
2017-09-29 10:34 |
2009-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291219
|
- |
|
tbdev
|
tbdev.net
|
Multiple open redirect vulnerabilities in TBDev.NET 01-01-08 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via (1) the returnto parameter to login.php o…
|
CWE-20
Improper Input Validation
|
CVE-2009-2138
|
2017-09-29 10:34 |
2009-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291220
|
- |
|
tbdev
|
tbdev.net
|
Multiple cross-site scripting (XSS) vulnerabilities in TBDev.NET 01-01-08 allow remote attackers to inject arbitrary web script or HTML via (1) the returnto parameter to makepoll.php, (2) the returnt…
|
CWE-79
Cross-site Scripting
|
CVE-2009-2141
|
2017-09-29 10:34 |
2009-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|