|
291231
|
- |
|
sappy.dk
|
impleo_music_collection
|
SQL injection vulnerability in admin/login.php in Impleo Music Collection 2.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the username parameter.
|
CWE-89
SQL Injection
|
CVE-2009-2154
|
2017-09-29 10:34 |
2009-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291232
|
- |
|
egyplus
|
7ammel
|
Multiple SQL injection vulnerabilities in cpanel/login.php in EgyPlus 7ammel (aka 7ml) 1.0.1 and earlier, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands v…
|
CWE-89
SQL Injection
|
CVE-2009-2167
|
2017-09-29 10:34 |
2009-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291233
|
- |
|
dream
|
radio_and_tv_player_addon_for_vbulletin
|
Cross-site scripting (XSS) vulnerability in forum/radioandtv.php in the Radio and TV Player addon for vBulletin allows remote registered users to inject arbitrary web script or HTML via the station p…
|
CWE-79
Cross-site Scripting
|
CVE-2009-2172
|
2017-09-29 10:34 |
2009-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291234
|
- |
|
gameis
|
carom3d
|
The LAN game feature in Carom3D 5.06 allows remote authenticated users to cause a denial of service (application hang) via a crafted HTTP request to TCP port 28012.
|
CWE-399
Resource Management Errors
|
CVE-2009-2173
|
2017-09-29 10:34 |
2009-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291235
|
- |
|
fuzzylime
|
fuzzylime_cms
|
Multiple directory traversal vulnerabilities in fuzzylime (cms) 3.03a and earlier, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via directory…
|
CWE-22
Path Traversal
|
CVE-2009-2176
|
2017-09-29 10:34 |
2009-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291236
|
- |
|
fuzzylime
|
fuzzylime_cms
|
code/display.php in fuzzylime (cms) 3.03a and earlier, when magic_quotes_gpc is disabled, allows remote attackers to conduct directory traversal attacks and overwrite arbitrary files via a "....//" (…
|
CWE-22
Path Traversal
|
CVE-2009-2177
|
2017-09-29 10:34 |
2009-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291237
|
- |
|
w2b
|
phpdatingclub
|
Cross-site scripting (XSS) vulnerability in website.php in phpDatingClub 3.7 allows remote attackers to inject arbitrary web script or HTML via the page parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2009-2178
|
2017-09-29 10:34 |
2009-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291238
|
- |
|
w2b
|
phpdatingclub
|
SQL injection vulnerability in search.php in phpDatingClub 3.7 allows remote attackers to execute arbitrary SQL commands via the sform[day] parameter.
|
CWE-89
SQL Injection
|
CVE-2009-2179
|
2017-09-29 10:34 |
2009-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291239
|
- |
|
pc4arb
|
pc4_uploader
|
Multiple directory traversal vulnerabilities in upfiles/index.php in Pc4 Uploader 10.0 and earlier allow remote attackers to read arbitrary files via (1) a .. (dot dot) or (2) absolute path in the fi…
|
CWE-22
Path Traversal
|
CVE-2009-2180
|
2017-09-29 10:34 |
2009-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291240
|
- |
|
campware.org
|
campsite
|
Cross-site scripting (XSS) vulnerability in admin-files/templates/list_dir.php in Campsite 3.3.0 RC1 allows remote attackers to inject arbitrary web script or HTML via the listbasedir parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2009-2181
|
2017-09-29 10:34 |
2009-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|