|
292231
|
- |
|
gowondesigns
|
leap
|
Multiple cross-site scripting (XSS) vulnerabilities in Leap CMS 0.1.4 allow remote attackers to inject arbitrary web script or HTML via (1) the msg parameter (aka the message in an article comment) o…
|
CWE-79
Cross-site Scripting
|
CVE-2009-1614
|
2017-09-29 10:34 |
2009-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292232
|
- |
|
gowondesigns
|
leap
|
Unrestricted file upload vulnerability in Leap CMS 0.1.4 allows remote attackers to execute arbitrary code by uploading a file with an executable extension via an admin.system.files (aka Manage Files…
|
NVD-CWE-Other
|
CVE-2009-1615
|
2017-09-29 10:34 |
2009-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292233
|
- |
|
teraway
|
linktracker
|
Teraway LinkTracker 1.0 allows remote attackers to bypass authentication and gain administrative access via a userid=1&lvl=1 value for the twLTadmin cookie.
|
CWE-287
Improper Authentication
|
CVE-2009-1617
|
2017-09-29 10:34 |
2009-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292234
|
- |
|
teraway
|
livehelp
|
Teraway LiveHelp 2.0 allows remote attackers to bypass authentication and gain administrative access via a pwd=&lvl=1&usr=&alias=admin&userid=1 value for the TWLHadmin cookie.
|
CWE-287
Improper Authentication
|
CVE-2009-1618
|
2017-09-29 10:34 |
2009-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292235
|
- |
|
teraway
|
filestream
|
Teraway FileStream 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the twFSadmin cookie to 1.
|
CWE-287
Improper Authentication
|
CVE-2009-1619
|
2017-09-29 10:34 |
2009-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292236
|
- |
|
ecshop
|
ecshop
|
SQL injection vulnerability in user.php in EcShop 2.5.0 allows remote attackers to execute arbitrary SQL commands via the order_sn parameter in an order_query action.
|
CWE-89
SQL Injection
|
CVE-2009-1622
|
2017-09-29 10:34 |
2009-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292237
|
- |
|
dew-code
|
dew-newphplinks
|
Cross-site scripting (XSS) vulnerability in index.php in Dew-NewPHPLinks 2.0 allows remote attackers to inject arbitrary web script or HTML via the PID parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2009-1623
|
2017-09-29 10:34 |
2009-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292238
|
- |
|
dew-code
|
dew-newphplinks
|
Directory traversal vulnerability in index.php in Dew-NewPHPLinks 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the show parameter.
|
CWE-22
Path Traversal
|
CVE-2009-1624
|
2017-09-29 10:34 |
2009-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292239
|
- |
|
davlin
|
thickbox_gallery
|
Directory traversal vulnerability in index.php in Thickbox Gallery 2 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the ln parameter.
|
CWE-22
Path Traversal
|
CVE-2009-1625
|
2017-09-29 10:34 |
2009-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292240
|
- |
|
will_kraft
|
ez-blog
|
SQL injection vulnerability in public/specific.php in EZ-Blog before Beta 2 20090427, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the category par…
|
CWE-89
SQL Injection
|
CVE-2009-1626
|
2017-09-29 10:34 |
2009-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|