|
292481
|
- |
|
egyplus
|
7ammel
|
Multiple SQL injection vulnerabilities in cpanel/login.php in EgyPlus 7ammel (aka 7ml) 1.0.1 and earlier, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands v…
|
CWE-89
SQL Injection
|
CVE-2009-2167
|
2017-09-29 10:34 |
2009-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292482
|
- |
|
dream
|
radio_and_tv_player_addon_for_vbulletin
|
Cross-site scripting (XSS) vulnerability in forum/radioandtv.php in the Radio and TV Player addon for vBulletin allows remote registered users to inject arbitrary web script or HTML via the station p…
|
CWE-79
Cross-site Scripting
|
CVE-2009-2172
|
2017-09-29 10:34 |
2009-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292483
|
- |
|
gameis
|
carom3d
|
The LAN game feature in Carom3D 5.06 allows remote authenticated users to cause a denial of service (application hang) via a crafted HTTP request to TCP port 28012.
|
CWE-399
Resource Management Errors
|
CVE-2009-2173
|
2017-09-29 10:34 |
2009-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292484
|
- |
|
fuzzylime
|
fuzzylime_cms
|
Multiple directory traversal vulnerabilities in fuzzylime (cms) 3.03a and earlier, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via directory…
|
CWE-22
Path Traversal
|
CVE-2009-2176
|
2017-09-29 10:34 |
2009-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292485
|
- |
|
fuzzylime
|
fuzzylime_cms
|
code/display.php in fuzzylime (cms) 3.03a and earlier, when magic_quotes_gpc is disabled, allows remote attackers to conduct directory traversal attacks and overwrite arbitrary files via a "....//" (…
|
CWE-22
Path Traversal
|
CVE-2009-2177
|
2017-09-29 10:34 |
2009-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292486
|
- |
|
w2b
|
phpdatingclub
|
Cross-site scripting (XSS) vulnerability in website.php in phpDatingClub 3.7 allows remote attackers to inject arbitrary web script or HTML via the page parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2009-2178
|
2017-09-29 10:34 |
2009-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292487
|
- |
|
w2b
|
phpdatingclub
|
SQL injection vulnerability in search.php in phpDatingClub 3.7 allows remote attackers to execute arbitrary SQL commands via the sform[day] parameter.
|
CWE-89
SQL Injection
|
CVE-2009-2179
|
2017-09-29 10:34 |
2009-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292488
|
- |
|
pc4arb
|
pc4_uploader
|
Multiple directory traversal vulnerabilities in upfiles/index.php in Pc4 Uploader 10.0 and earlier allow remote attackers to read arbitrary files via (1) a .. (dot dot) or (2) absolute path in the fi…
|
CWE-22
Path Traversal
|
CVE-2009-2180
|
2017-09-29 10:34 |
2009-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292489
|
- |
|
campware.org
|
campsite
|
Cross-site scripting (XSS) vulnerability in admin-files/templates/list_dir.php in Campsite 3.3.0 RC1 allows remote attackers to inject arbitrary web script or HTML via the listbasedir parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2009-2181
|
2017-09-29 10:34 |
2009-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292490
|
- |
|
campware.org
|
campsite
|
Multiple PHP remote file inclusion vulnerabilities in Campsite 3.3.0 RC1 allow remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[g_campsiteDir] parameter to (1) ad_popup.php, (2…
|
CWE-94
Code Injection
|
CVE-2009-2182
|
2017-09-29 10:34 |
2009-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|