|
287851
|
- |
|
dmxready
|
member_directory_manager
|
SQL injection vulnerability in CategoryManager/upload_image_category.asp in DMXReady Member Directory Manager 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the cid par…
|
CWE-89
SQL Injection
|
CVE-2009-0427
|
2017-10-19 10:30 |
2009-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287852
|
- |
|
dmxready
|
secure_document_library
|
SQL injection vulnerability in CategoryManager/upload_image_category.asp in DMXReady Secure Document Library 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the cid para…
|
CWE-89
SQL Injection
|
CVE-2009-0428
|
2017-10-19 10:30 |
2009-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287853
|
- |
|
wholehogsoftware
|
ware_support
|
Multiple SQL injection vulnerabilities in admin/login_submit.php in Whole Hog Ware Support 1.x allow remote attackers to execute arbitrary SQL commands via (1) the uid parameter (aka Username field) …
|
CWE-89
SQL Injection
|
CVE-2009-0458
|
2017-10-19 10:30 |
2009-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287854
|
- |
|
wholehogsoftware
|
password_protect
|
Multiple SQL injection vulnerabilities in admin/login_submit.php in Whole Hog Password Protect: Enhanced 1.x allow remote attackers to execute arbitrary SQL commands via (1) the uid parameter (aka Us…
|
CWE-89
SQL Injection
|
CVE-2009-0459
|
2017-10-19 10:30 |
2009-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287855
|
- |
|
wholehogsoftware
|
ware_support
|
Whole Hog Ware Support 1.x allows remote attackers to bypass authentication and obtain administrative access via an integer value in the adminid cookie.
|
CWE-287
Improper Authentication
|
CVE-2009-0460
|
2017-10-19 10:30 |
2009-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287856
|
- |
|
wholehogsoftware
|
password_protect
|
Whole Hog Password Protect: Enhanced 1.x allows remote attackers to bypass authentication and obtain administrative access via an integer value in the adminid cookie.
|
CWE-287
Improper Authentication
|
CVE-2009-0461
|
2017-10-19 10:30 |
2009-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287857
|
- |
|
geovision
|
livex_activex_control
|
Directory traversal vulnerability in the SnapShotToFile method in the GeoVision LiveX (aka LiveX_v8200) ActiveX control 8.1.2 and 8.2.0 in LIVEX_~1.OCX allows remote attackers to create or overwrite …
|
CWE-22
Path Traversal
|
CVE-2009-0865
|
2017-10-19 10:30 |
2009-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287858
|
- |
|
freebsd
|
freebsd
|
The IATA (ata) driver in FreeBSD 6.0 and 8.0, when read access to /dev is available, allows local users to cause a denial of service (kernel panic) via a certain IOCTL request with a large count, whi…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-2649
|
2017-10-19 10:30 |
2009-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287859
|
- |
|
loudblog
|
loudblog
|
Eval injection vulnerability in loudblog/inc/parse_old.php in Loudblog 0.8.0 and earlier allows remote attackers to execute arbitrary PHP code via the template parameter.
|
CWE-89
SQL Injection
|
CVE-2008-0139
|
2017-10-19 10:30 |
2008-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287860
|
- |
|
tutos
|
tutos
|
TUTOS 1.3 does not restrict access to php/admin/cmd.php, which allows remote attackers to execute arbitrary shell commands via the cmd parameter in a direct request.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-0148
|
2017-10-19 10:30 |
2008-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|