|
291331
|
- |
|
humayun_shabbir
|
php-cms_project
|
SQL injection vulnerability in admin/login.php in PHP-CMS Project 1 allows remote attackers to execute arbitrary SQL commands via the username parameter.
|
CWE-89
SQL Injection
|
CVE-2009-0407
|
2017-09-29 10:33 |
2009-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291332
|
- |
|
hp
|
hp-ux
|
The IPv6 Neighbor Discovery Protocol (NDP) implementation in HP HP-UX B.11.11, B.11.23, and B.11.31 does not validate the origin of Neighbor Discovery messages, which allows remote attackers to cause…
|
CWE-20
Improper Input Validation
|
CVE-2009-0418
|
2017-09-29 10:33 |
2009-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291333
|
- |
|
rd-media
|
rd-autos
|
SQL injection vulnerability in the RD-Autos (com_rdautos) 1.5.5 Stable component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.
|
CWE-89
SQL Injection
|
CVE-2009-0420
|
2017-09-29 10:33 |
2009-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291334
|
- |
|
joomla
|
com_eventing
|
SQL injection vulnerability in the Eventing (com_eventing) 1.6.x component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php.
|
CWE-89
SQL Injection
|
CVE-2009-0421
|
2017-09-29 10:33 |
2009-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291335
|
- |
|
kevin_walker
|
php_photo_album
|
Directory traversal vulnerability in index.php in Php Photo Album (PHPPA) 0.8 BETA allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the preview parameter.
|
CWE-22
Path Traversal
|
CVE-2009-0423
|
2017-09-29 10:33 |
2009-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291336
|
- |
|
blue_eye_cms
|
blue_eye_cms
|
SQL injection vulnerability in index.php in Blue Eye CMS 1.0.0 and earlier allows remote attackers to execute arbitrary SQL commands via the clanek parameter.
|
CWE-89
SQL Injection
|
CVE-2009-0425
|
2017-09-29 10:33 |
2009-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291337
|
- |
|
technote
|
technote
|
PHP remote file inclusion vulnerability in skin_shop/standard/2_view_body/body_default.php in TECHNOTE 7.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via…
|
CWE-94
Code Injection
|
CVE-2009-0441
|
2017-09-29 10:33 |
2009-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291338
|
- |
|
phpbbbook
|
phpbbbook
|
Directory traversal vulnerability in bbcode.php in PHPbbBook 1.3 and 1.3h allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the l parameter.
|
CWE-22
Path Traversal
|
CVE-2009-0442
|
2017-09-29 10:33 |
2009-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291339
|
- |
|
elecard
|
elecard_avc_hd_player
|
Stack-based buffer overflow in Elecard AVC HD PLAYER 5.5.90116 allows remote attackers to execute arbitrary code via an M3U file containing a long string in a URL.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-0443
|
2017-09-29 10:33 |
2009-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291340
|
- |
|
dreampics
|
gallery_builder
|
SQL injection vulnerability in index.php in Dreampics Gallery Builder allows remote attackers to execute arbitrary SQL commands via the exhibition_id parameter in a gallery.viewPhotos action.
|
CWE-89
SQL Injection
|
CVE-2009-0445
|
2017-09-29 10:33 |
2009-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|