|
291361
|
- |
|
mivaco
|
com_portfol
|
SQL injection vulnerability in the Portfol (com_portfol) 1.2 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the vcatid parameter in a viewcategory action to index…
|
CWE-89
SQL Injection
|
CVE-2009-0494
|
2017-09-29 10:33 |
2009-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291362
|
- |
|
it747
|
realtor_747
|
PHP remote file inclusion vulnerability in include/define.php in REALTOR 747 4.11 allows remote attackers to execute arbitrary PHP code via a URL in the INC_DIR parameter.
|
CWE-94
Code Injection
|
CVE-2009-0495
|
2017-09-29 10:33 |
2009-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291363
|
- |
|
minitdesign
|
virtual_guestbook
|
Virtual GuestBook (vgbook) 2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request to gu…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-0498
|
2017-09-29 10:33 |
2009-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291364
|
- |
|
webframe
|
webframe
|
Multiple PHP remote file inclusion vulnerabilities in WebFrame 0.76 allow remote attackers to execute arbitrary PHP code via a URL in the classFiles parameter to (1) admin/doc/index.php, (2) index.ph…
|
CWE-94
Code Injection
|
CVE-2009-0513
|
2017-09-29 10:33 |
2009-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291365
|
- |
|
webframe
|
webframe
|
Multiple directory traversal vulnerabilities in WebFrame 0.76 allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the (1) currentmod and (2) LANG …
|
CWE-22
Path Traversal
|
CVE-2009-0514
|
2017-09-29 10:33 |
2009-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291366
|
- |
|
yanocc
|
yanocc
|
Directory traversal vulnerability in check_lang.php in Yet Another NOCC (YANOCC) 0.1.0 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang …
|
CWE-22
Path Traversal
|
CVE-2009-0515
|
2017-09-29 10:33 |
2009-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291367
|
- |
|
vmware
|
vmware_esx vmware_esxi vmware_virtualcenter
|
VI Client in VMware VirtualCenter before 2.5 Update 4, VMware ESXi 3.5 before Update 4, and VMware ESX 3.5 before Update 4 retains the VirtualCenter Server password in process memory, which might all…
|
CWE-200
Information Exposure
|
CVE-2009-0518
|
2017-09-29 10:33 |
2009-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291368
|
- |
|
adobe
|
air flash_player flash_player_for_linux flex
|
Unspecified vulnerability in Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 allows remote attackers to cause a denial of service (browser crash) or possibly execute arbitrary code…
|
CWE-20
Improper Input Validation
|
CVE-2009-0519
|
2017-09-29 10:33 |
2009-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291369
|
- |
|
adobe
|
air flash_player flash_player_for_linux flex
|
Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 does not properly remove references to destroyed objects during Shockwave Flash file processing, which allows remote attackers to ex…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-0520
|
2017-09-29 10:33 |
2009-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291370
|
- |
|
adobe
|
air flash_player flash_player_for_linux flex
|
Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 on Windows allows remote attackers to trick a user into visiting an arbitrary URL via an unspecified manipulation of the "mouse poin…
|
NVD-CWE-Other
|
CVE-2009-0522
|
2017-09-29 10:33 |
2009-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|