|
291281
|
- |
|
warhound
|
walking_club
|
SQL injection vulnerability in login.aspx in WarHound Walking Club allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.
|
CWE-89
SQL Injection
|
CVE-2009-0281
|
2017-09-29 10:33 |
2009-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291282
|
- |
|
opengoo
|
opengoo
|
Directory traversal vulnerability in upgrade/index.php in OpenGoo 1.1, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot…
|
CWE-22
Path Traversal
|
CVE-2009-0286
|
2017-09-29 10:33 |
2009-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291283
|
- |
|
sir
|
gnuboard
|
Directory traversal vulnerability in common.php in SIR GNUBoard 4.31.03 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the g4_path parameter. NOTE: in som…
|
CWE-22
Path Traversal
|
CVE-2009-0290
|
2017-09-29 10:33 |
2009-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291284
|
- |
|
shop-inet
|
shop-inet
|
SQL injection vulnerability in show_cat2.php in SHOP-INET 4 allows remote attackers to execute arbitrary SQL commands via the grid parameter.
|
CWE-89
SQL Injection
|
CVE-2009-0292
|
2017-09-29 10:33 |
2009-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291285
|
- |
|
wazzum
|
wazzum_dating_software
|
SQL injection vulnerability in profile_view.php in Wazzum Dating Software, possibly 2.0, allows remote attackers to execute arbitrary SQL commands via the userid parameter.
|
CWE-89
SQL Injection
|
CVE-2009-0293
|
2017-09-29 10:33 |
2009-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291286
|
- |
|
itlpoll
|
itpoll
|
SQL injection vulnerability in index.php in Information Technology Light Poll Information (ITLPoll) 2.7 Stable 2, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL c…
|
CWE-89
SQL Injection
|
CVE-2009-0295
|
2017-09-29 10:33 |
2009-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291287
|
- |
|
gempar
|
script_toko_online
|
SQL injection vulnerability in shop_display_products.php in Script Toko Online 5.01 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.
|
CWE-89
SQL Injection
|
CVE-2009-0296
|
2017-09-29 10:33 |
2009-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291288
|
- |
|
clicktech
|
clickauction
|
SQL injection vulnerability in login_check.asp in ClickAuction allows remote attackers to execute arbitrary SQL commands via the (1) txtEmail and (2) txtPassword parameters. NOTE: some of these deta…
|
CWE-89
SQL Injection
|
CVE-2009-0297
|
2017-09-29 10:33 |
2009-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291289
|
- |
|
mw6_technologies
|
barcode_activex
|
Heap-based buffer overflow in MW6 Technologies Barcode ActiveX control (Barcode.MW6Barcode.1, Barcode.dll) 3.0.0.1 allows remote attackers to execute arbitrary code via a long Supplement property.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-0298
|
2017-09-29 10:33 |
2009-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291290
|
- |
|
groonesworld
|
glinks
|
SQL injection vulnerability in index.php in Groone GLinks 2.1 allows remote attackers to execute arbitrary SQL commands via the cat parameter.
|
CWE-89
SQL Injection
|
CVE-2009-0299
|
2017-09-29 10:33 |
2009-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|