|
287611
|
- |
|
mntechsolutions
|
theeta_cms
|
Multiple SQL injection vulnerabilities in Theeta CMS, possibly 0.01, allow remote attackers to execute arbitrary SQL commands via the start parameter to (1) forum.php and (2) thread.php in community/…
|
CWE-89
SQL Injection
|
CVE-2009-4783
|
2018-10-11 04:49 |
2010-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287612
|
- |
|
ryan_haudenschilt
|
family_connections
|
Multiple SQL injection vulnerabilities in Family Connections (aka FCMS) before 1.8.2 allow remote attackers to execute arbitrary SQL commands via the (1) letter parameter to addressbook.php, (2) id p…
|
CWE-89
SQL Injection
|
CVE-2009-4791
|
2018-10-11 04:49 |
2010-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287613
|
- |
|
community_cms
|
community_cms
|
Multiple SQL injection vulnerabilities in Community CMS 0.5 allow remote attackers to execute arbitrary SQL commands via the (1) article_id parameter to view.php and the (2) a parameter in an event a…
|
CWE-89
SQL Injection
|
CVE-2009-4794
|
2018-10-11 04:49 |
2010-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287614
|
- |
|
glfusion
|
glfusion
|
Multiple SQL injection vulnerabilities in the ExecuteQueries function in private/system/classes/listfactory.class.php in glFusion 1.1.2 and earlier allow remote attackers to execute arbitrary SQL com…
|
CWE-89
SQL Injection
|
CVE-2009-4796
|
2018-10-11 04:49 |
2010-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287615
|
- |
|
will_kraft
|
ez-blog
|
EZ-Blog Beta 1 does not require authentication, which allows remote attackers to create or delete arbitrary posts via requests to PHP scripts.
|
CWE-287
Improper Authentication
|
CVE-2009-4801
|
2018-10-11 04:49 |
2010-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287616
|
- |
|
will_kraft
|
ez-blog
|
Multiple SQL injection vulnerabilities in EZ-Blog Beta 1, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via (1) the storyid parameter to public/view.php …
|
CWE-89
SQL Injection
|
CVE-2009-4805
|
2018-10-11 04:49 |
2010-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287617
|
- |
|
toutvirtual
|
virtualiq
|
ToutVirtual VirtualIQ Pro before 3.5 build 8691 does not require administrative authentication for JBoss console access, which allows remote attackers to execute arbitrary commands via requests to (1…
|
CWE-287
Improper Authentication
|
CVE-2009-4843
|
2018-10-11 04:49 |
2010-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287618
|
- |
|
toutvirtual
|
virtualiq
|
ToutVirtual VirtualIQ Pro 3.2 build 7882 does not restrict access to the /status URI on port 9080, which allows remote attackers to obtain sensitive Tomcat information via a direct request.
|
CWE-200
Information Exposure
|
CVE-2009-4844
|
2018-10-11 04:49 |
2010-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287619
|
- |
|
toutvirtual
|
virtualiq
|
The configuration page in ToutVirtual VirtualIQ Pro 3.2 build 7882 contains cleartext SSH credentials, which allows remote attackers to obtain sensitive information by reading the username and passwo…
|
CWE-310
Cryptographic Issues
|
CVE-2009-4845
|
2018-10-11 04:49 |
2010-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287620
|
- |
|
toutvirtual
|
virtualiq
|
Multiple cross-site scripting (XSS) vulnerabilities in ToutVirtual VirtualIQ Pro 3.2 build 7882 and 3.5 build 8691 allow remote attackers to inject arbitrary web script or HTML via the (1) userId par…
|
CWE-79
Cross-site Scripting
|
CVE-2009-4848
|
2018-10-11 04:49 |
2010-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|