|
291371
|
- |
|
adobe
|
air flash_player flash_player_for_linux flex
|
Per: http://www.adobe.com/support/security/bulletins/apsb09-01.html
"This update resolves a Windows-only issue with mouse pointer display that could potentially contribute to a Clickjacking attack…
|
NVD-CWE-Other
|
CVE-2009-0522
|
2017-09-29 10:33 |
2009-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291372
|
- |
|
adaptcms
|
adaptcms
|
Multiple cross-site scripting (XSS) vulnerabilities in index.php in AdaptCMS Lite 1.4 allow remote attackers to inject arbitrary web script or HTML via the (1) url and (2) acuparam parameters, and (3…
|
CWE-79
Cross-site Scripting
|
CVE-2009-0526
|
2017-09-29 10:33 |
2009-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291373
|
- |
|
adaptcms
|
adaptcms
|
PHP remote file inclusion vulnerability in plugins/rss_importer_functions.php in AdaptCMS Lite 1.4 allows remote attackers to execute arbitrary PHP code via a URL in the sitepath parameter.
|
CWE-94
Code Injection
|
CVE-2009-0527
|
2017-09-29 10:33 |
2009-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291374
|
- |
|
rhadrix
|
if-cms
|
SQL injection vulnerability in frame.php in Rhadrix If-CMS 2.07 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2009-0528
|
2017-09-29 10:33 |
2009-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291375
|
- |
|
electrictoad
|
snippetmaster_webpage_editor
|
Cross-site scripting (XSS) vulnerability in index.php in SnippetMaster Webpage Editor 2.2.2 allows remote attackers to inject arbitrary web script or HTML via the language parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2009-0529
|
2017-09-29 10:33 |
2009-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291376
|
- |
|
electrictoad
|
snippetmaster_webpage_editor
|
Multiple PHP remote file inclusion vulnerabilities in SnippetMaster 2.2.2, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) _SESSION[SCRIPT_…
|
CWE-94
Code Injection
|
CVE-2009-0530
|
2017-09-29 10:33 |
2009-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291377
|
- |
|
ontarioabandonedplaces
|
a_better_member-based_asp_photo_gallery
|
SQL injection vulnerability in gallery/view.asp in A Better Member-Based ASP Photo Gallery before 1.2 allows remote attackers to execute arbitrary SQL commands via the entry parameter.
|
CWE-89
SQL Injection
|
CVE-2009-0531
|
2017-09-29 10:33 |
2009-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291378
|
- |
|
ontarioabandonedplaces
|
a_better_member-based_asp_photo_gallery
|
Version 1.2 released which fixed the SQL injection bug. It also properly deletes thumbnails for invalid filetypes (invalid files were removed but the thumbnails remained).
http://www.ontarioabando…
|
CWE-89
SQL Injection
|
CVE-2009-0531
|
2017-09-29 10:33 |
2009-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291379
|
- |
|
flexcms
|
flexcms
|
SQL injection vulnerability in FlexCMS allows remote attackers to execute arbitrary SQL commands via the catId parameter.
|
CWE-89
SQL Injection
|
CVE-2009-0534
|
2017-09-29 10:33 |
2009-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291380
|
- |
|
extrosoft
|
thyme
|
Directory traversal vulnerability in export.php in Thyme 1.3 and earlier, when register_globals is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the export_to parame…
|
CWE-22
Path Traversal
|
CVE-2009-0535
|
2017-09-29 10:33 |
2009-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|