|
292611
|
- |
|
it747
|
realtor_747
|
PHP remote file inclusion vulnerability in include/define.php in REALTOR 747 4.11 allows remote attackers to execute arbitrary PHP code via a URL in the INC_DIR parameter.
|
CWE-94
Code Injection
|
CVE-2009-0495
|
2017-09-29 10:33 |
2009-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292612
|
- |
|
minitdesign
|
virtual_guestbook
|
Virtual GuestBook (vgbook) 2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request to gu…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-0498
|
2017-09-29 10:33 |
2009-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292613
|
- |
|
webframe
|
webframe
|
Multiple PHP remote file inclusion vulnerabilities in WebFrame 0.76 allow remote attackers to execute arbitrary PHP code via a URL in the classFiles parameter to (1) admin/doc/index.php, (2) index.ph…
|
CWE-94
Code Injection
|
CVE-2009-0513
|
2017-09-29 10:33 |
2009-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292614
|
- |
|
webframe
|
webframe
|
Multiple directory traversal vulnerabilities in WebFrame 0.76 allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the (1) currentmod and (2) LANG …
|
CWE-22
Path Traversal
|
CVE-2009-0514
|
2017-09-29 10:33 |
2009-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292615
|
- |
|
yanocc
|
yanocc
|
Directory traversal vulnerability in check_lang.php in Yet Another NOCC (YANOCC) 0.1.0 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang …
|
CWE-22
Path Traversal
|
CVE-2009-0515
|
2017-09-29 10:33 |
2009-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292616
|
- |
|
vmware
|
vmware_esx vmware_esxi vmware_virtualcenter
|
VI Client in VMware VirtualCenter before 2.5 Update 4, VMware ESXi 3.5 before Update 4, and VMware ESX 3.5 before Update 4 retains the VirtualCenter Server password in process memory, which might all…
|
CWE-200
Information Exposure
|
CVE-2009-0518
|
2017-09-29 10:33 |
2009-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292617
|
- |
|
adobe
|
air flash_player flash_player_for_linux flex
|
Unspecified vulnerability in Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 allows remote attackers to cause a denial of service (browser crash) or possibly execute arbitrary code…
|
CWE-20
Improper Input Validation
|
CVE-2009-0519
|
2017-09-29 10:33 |
2009-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292618
|
- |
|
adobe
|
air flash_player flash_player_for_linux flex
|
Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 does not properly remove references to destroyed objects during Shockwave Flash file processing, which allows remote attackers to ex…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-0520
|
2017-09-29 10:33 |
2009-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292619
|
- |
|
adobe
|
air flash_player flash_player_for_linux flex
|
Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 on Windows allows remote attackers to trick a user into visiting an arbitrary URL via an unspecified manipulation of the "mouse poin…
|
NVD-CWE-Other
|
CVE-2009-0522
|
2017-09-29 10:33 |
2009-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292620
|
- |
|
adobe
|
air flash_player flash_player_for_linux flex
|
Per: http://www.adobe.com/support/security/bulletins/apsb09-01.html
"This update resolves a Windows-only issue with mouse pointer display that could potentially contribute to a Clickjacking attack…
|
NVD-CWE-Other
|
CVE-2009-0522
|
2017-09-29 10:33 |
2009-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|