|
292561
|
- |
|
mozilla
|
firefox
|
Mozilla Firefox 3.x before 3.0.6 does not properly implement the (1) no-store and (2) no-cache Cache-Control directives, which allows local users to obtain sensitive information by using the (a) back…
|
CWE-200
Information Exposure
|
CVE-2009-0358
|
2017-09-29 10:33 |
2009-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292562
|
- |
|
ubuntu
|
ubuntu_linux
|
nm-applet.conf in GNOME NetworkManager before 0.7.0.99 contains an incorrect deny setting, which allows local users to discover (1) network connection passwords and (2) pre-shared keys via calls to t…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-0365
|
2017-09-29 10:33 |
2009-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292563
|
- |
|
microsoft
|
internet_explorer
|
Microsoft Internet Explorer 7 allows remote attackers to trick a user into visiting an arbitrary URL via an onclick action that moves a crafted element to the current mouse position, related to a "Cl…
|
NVD-CWE-Other
|
CVE-2009-0369
|
2017-09-29 10:33 |
2009-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292564
|
- |
|
ibm
|
aix
|
Multiple unspecified vulnerabilities in IBM AIX 5.2.0 through 6.1.2 allow local users to append data to arbitrary files, related to (1) rmsock and (2) rmsock64 not creating "secure log files."
|
NVD-CWE-noinfo
|
CVE-2009-0370
|
2017-09-29 10:33 |
2009-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292565
|
- |
|
sitexs_cms
|
sitexs_cms
|
Directory traversal vulnerability in post.php in SiteXS CMS 0.1.1 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the type parameter.
|
CWE-22
Path Traversal
|
CVE-2009-0371
|
2017-09-29 10:33 |
2009-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292566
|
- |
|
memht
|
memht_portal
|
Unrestricted file upload vulnerability in index.php in Miltenovik Manojlo MemHT Portal 4.0.1 and earlier allows remote authenticated users to execute arbitrary code by uploading a file with an execut…
|
CWE-20
Improper Input Validation
|
CVE-2009-0372
|
2017-09-29 10:33 |
2009-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292567
|
- |
|
elearningforce
|
flash_magazine_deluxe
|
SQL injection vulnerability in the ElearningForce Flash Magazine Deluxe (com_flashmagazinedeluxe) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the mag_id parame…
|
CWE-89
SQL Injection
|
CVE-2009-0373
|
2017-09-29 10:33 |
2009-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292568
|
- |
|
joomla
|
com_pcchess
|
SQL injection vulnerability in the Prince Clan Chess Club (com_pcchess) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the game_id parameter in a showgame action …
|
CWE-89
SQL Injection
|
CVE-2009-0379
|
2017-09-29 10:33 |
2009-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292569
|
- |
|
bazaarbuilder
|
ecommerce_shopping_cart
|
SQL injection vulnerability in the BazaarBuilder Ecommerce Shopping Cart (com_prod) 5.0 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid parameter in a prod…
|
CWE-89
SQL Injection
|
CVE-2009-0381
|
2017-09-29 10:33 |
2009-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292570
|
- |
|
adam_tomecek
|
ownrs
|
SQL injection vulnerability in autor.php in OwnRS CMS 1.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2009-0384
|
2017-09-29 10:33 |
2009-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|