|
287681
|
- |
|
community_cms
|
community_cms
|
Multiple SQL injection vulnerabilities in Community CMS 0.5 allow remote attackers to execute arbitrary SQL commands via the (1) article_id parameter to view.php and the (2) a parameter in an event a…
|
CWE-89
SQL Injection
|
CVE-2009-4794
|
2018-10-11 04:49 |
2010-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287682
|
- |
|
glfusion
|
glfusion
|
Multiple SQL injection vulnerabilities in the ExecuteQueries function in private/system/classes/listfactory.class.php in glFusion 1.1.2 and earlier allow remote attackers to execute arbitrary SQL com…
|
CWE-89
SQL Injection
|
CVE-2009-4796
|
2018-10-11 04:49 |
2010-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287683
|
- |
|
will_kraft
|
ez-blog
|
EZ-Blog Beta 1 does not require authentication, which allows remote attackers to create or delete arbitrary posts via requests to PHP scripts.
|
CWE-287
Improper Authentication
|
CVE-2009-4801
|
2018-10-11 04:49 |
2010-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287684
|
- |
|
will_kraft
|
ez-blog
|
Multiple SQL injection vulnerabilities in EZ-Blog Beta 1, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via (1) the storyid parameter to public/view.php …
|
CWE-89
SQL Injection
|
CVE-2009-4805
|
2018-10-11 04:49 |
2010-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287685
|
- |
|
toutvirtual
|
virtualiq
|
ToutVirtual VirtualIQ Pro before 3.5 build 8691 does not require administrative authentication for JBoss console access, which allows remote attackers to execute arbitrary commands via requests to (1…
|
CWE-287
Improper Authentication
|
CVE-2009-4843
|
2018-10-11 04:49 |
2010-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287686
|
- |
|
toutvirtual
|
virtualiq
|
ToutVirtual VirtualIQ Pro 3.2 build 7882 does not restrict access to the /status URI on port 9080, which allows remote attackers to obtain sensitive Tomcat information via a direct request.
|
CWE-200
Information Exposure
|
CVE-2009-4844
|
2018-10-11 04:49 |
2010-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287687
|
- |
|
toutvirtual
|
virtualiq
|
The configuration page in ToutVirtual VirtualIQ Pro 3.2 build 7882 contains cleartext SSH credentials, which allows remote attackers to obtain sensitive information by reading the username and passwo…
|
CWE-310
Cryptographic Issues
|
CVE-2009-4845
|
2018-10-11 04:49 |
2010-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287688
|
- |
|
toutvirtual
|
virtualiq
|
Multiple cross-site scripting (XSS) vulnerabilities in ToutVirtual VirtualIQ Pro 3.2 build 7882 and 3.5 build 8691 allow remote attackers to inject arbitrary web script or HTML via the (1) userId par…
|
CWE-79
Cross-site Scripting
|
CVE-2009-4848
|
2018-10-11 04:49 |
2010-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287689
|
- |
|
toutvirtual
|
virtualiq
|
Multiple cross-site request forgery (CSRF) vulnerabilities in ToutVirtual VirtualIQ Pro 3.2 build 7882 and 3.5 build 8691 allow remote attackers to hijack the authentication of administrators for req…
|
CWE-352
Origin Validation Error
|
CVE-2009-4849
|
2018-10-11 04:49 |
2010-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287690
|
- |
|
bernhard_frohlich
|
phpcom
|
Multiple SQL injection vulnerabilities in phpCommunity 2 2.1.8, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via (1) the forum_id parameter in a forum a…
|
CWE-89
SQL Injection
|
CVE-2009-4884
|
2018-10-11 04:49 |
2010-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|