|
292361
|
- |
|
ideal
|
com_moofaq
|
Directory traversal vulnerability in includes/file_includer.php in the Ideal MooFAQ (com_moofaq) component 1.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the fi…
|
CWE-22
Path Traversal
|
CVE-2009-2015
|
2017-09-29 10:34 |
2009-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292362
|
- |
|
virtuenetz
|
virtue_shopping_mall
|
SQL injection vulnerability in products.php in Virtue Shopping Mall allows remote attackers to execute arbitrary SQL commands via the cid parameter.
|
CWE-89
SQL Injection
|
CVE-2009-2016
|
2017-09-29 10:34 |
2009-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292363
|
- |
|
virtuenetz
|
virtue_book_store
|
SQL injection vulnerability in products.php in Virtue Book Store allows remote attackers to execute arbitrary SQL commands via the cid parameter.
|
CWE-89
SQL Injection
|
CVE-2009-2017
|
2017-09-29 10:34 |
2009-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292364
|
- |
|
jaredeckersley
|
mycars
|
SQL injection vulnerability in admin/index.php in Jared Eckersley MyCars, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the authuserid parameter.
|
CWE-89
SQL Injection
|
CVE-2009-2018
|
2017-09-29 10:34 |
2009-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292365
|
- |
|
virtuenetz
|
virtue_news_manager
|
SQL injection vulnerability in news_detail.php in Virtue News Manager allows remote attackers to execute arbitrary SQL commands via the nid parameter.
|
CWE-89
SQL Injection
|
CVE-2009-2019
|
2017-09-29 10:34 |
2009-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292366
|
- |
|
virtuenetz
|
virtue_news_manager
|
Cross-site scripting (XSS) vulnerability in news_detail.php in Virtue News Manager allows remote attackers to inject arbitrary web script or HTML via the nid parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2009-2020
|
2017-09-29 10:34 |
2009-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292367
|
- |
|
virtuenetz
|
virtue_classifieds
|
SQL injection vulnerability in search.php in Virtue Classifieds allows remote attackers to execute arbitrary SQL commands via the category parameter.
|
CWE-89
SQL Injection
|
CVE-2009-2021
|
2017-09-29 10:34 |
2009-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292368
|
- |
|
fipsasp
|
fipscms_light
|
fipsCMS Light 2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file and obtain sensitive information via a …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-2022
|
2017-09-29 10:34 |
2009-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292369
|
- |
|
shop-script
|
shop-script
|
SQL injection vulnerability in index.php in Shop-Script Pro 2.12, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the current_currency parameter.
|
CWE-89
SQL Injection
|
CVE-2009-2023
|
2017-09-29 10:34 |
2009-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292370
|
- |
|
vt.rovno
|
asp_vt_auth
|
Vlad Titarenko ASP VT Auth 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file and obtain usernames and p…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-2024
|
2017-09-29 10:34 |
2009-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|