|
292221
|
- |
|
kalptarudemos
|
million_dollar_text_links
|
Million Dollar Text Links 1.0 does not properly restrict administrator access to admin.home.php, which allows remote attackers to bypass intended restrictions and gain privileges via a direct request…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-1582
|
2017-09-29 10:34 |
2009-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292222
|
- |
|
kalptarudemos
|
php_site_lock
|
index.php in PHP Site Lock 2.0 allows remote attackers to bypass authentication and obtain administrative access by setting the login_id, group_id, login_name, user_id, and user_type cookies to certa…
|
CWE-287
Improper Authentication
|
CVE-2009-1587
|
2017-09-29 10:34 |
2009-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292223
|
- |
|
electrasoft
|
32bit_ftp
|
Stack-based buffer overflow in ElectraSoft 32bit FTP 09.04.24 allows remote FTP servers to execute arbitrary code via a long banner. NOTE: this might overlap CVE-2003-1368.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-1592
|
2017-09-29 10:34 |
2009-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292224
|
- |
|
pablosoftwaresolutions
|
quick\'n_easy_mail_server
|
Pablo Software Solutions Quick 'n Easy Mail Server 3.3 allows remote attackers to cause a denial of service (daemon outage or CPU consumption) via multiple long SMTP commands, as demonstrated by HELO…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-1602
|
2017-09-29 10:34 |
2009-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292225
|
- |
|
linkbase
|
linkbase
|
Cross-site scripting (XSS) vulnerability in the administrator panel in phpForm.net LinkBase 2.0 allows remote attackers to inject arbitrary web script or HTML via the username in a registration, whic…
|
CWE-79
Cross-site Scripting
|
CVE-2009-1607
|
2017-09-29 10:34 |
2009-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292226
|
- |
|
battleblog
|
battle_blog
|
Unrestricted file upload vulnerability in admin/uploadform.asp in Battle Blog 1.25 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing i…
|
CWE-20
Improper Input Validation
|
CVE-2009-1609
|
2017-09-29 10:34 |
2009-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292227
|
- |
|
jobscript
|
job_script_job_board_software
|
admin/changepassword.php in Job Script Job Board Software 2.0 allows remote attackers to change the administrator password and gain administrator privileges via a direct request.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-1610
|
2017-09-29 10:34 |
2009-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292228
|
- |
|
electrasoft
|
32bit_ftp
|
Stack-based buffer overflow in ElectraSoft 32bit FTP 09.04.24 allows remote FTP servers to execute arbitrary code via a long 257 reply to a CWD command.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-1611
|
2017-09-29 10:34 |
2009-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292229
|
- |
|
baofeng
|
storm
|
Stack-based buffer overflow in the MPS.StormPlayer.1 ActiveX control in mps.dll 3.9.4.27 in Baofeng Storm allows remote attackers to execute arbitrary code via a long argument to the OnBeforeVideoDow…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-1612
|
2017-09-29 10:34 |
2009-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292230
|
- |
|
gowondesigns
|
leap
|
Multiple SQL injection vulnerabilities in leap.php in Leap CMS 0.1.4, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) searchterm or (2) email p…
|
CWE-89
SQL Injection
|
CVE-2009-1613
|
2017-09-29 10:34 |
2009-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|