|
287631
|
- |
|
zen-cart
|
zen_cart
|
extras/ipn_test_return.php in Zen Cart allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message.
|
CWE-200
Information Exposure
|
CVE-2009-4322
|
2018-10-11 04:49 |
2009-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287632
|
- |
|
liran_tal
|
daloradius
|
Cross-site scripting (XSS) vulnerability in daloradius-users/login.php in daloRADIUS 0.9-8 and earlier allows remote attackers to inject arbitrary web script or HTML via the error parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2009-4347
|
2018-10-11 04:49 |
2009-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287633
|
- |
|
wscreator
|
wscreator
|
SQL injection vulnerability in ADMIN/loginaction.php in WSCreator 1.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the Email (aka username) parame…
|
CWE-89
SQL Injection
|
CVE-2009-4351
|
2018-10-11 04:49 |
2009-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287634
|
- |
|
nullsoft
|
winamp
|
Multiple integer overflows in the jpeg.w5s and png.w5s filters in Winamp before 5.57 allow remote attackers to execute arbitrary code via malformed (1) JPEG or (2) PNG data in an MP3 file.
|
CWE-189
Numeric Errors
|
CVE-2009-4356
|
2018-10-11 04:49 |
2009-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287635
|
- |
|
sitecore
|
staging_module
|
The Staging Webservice ("sitecore modules/staging/service/api.asmx") in Sitecore Staging Module 5.4.0 rev.080625 and earlier allows remote attackers to bypass authentication and (1) upload files, (2)…
|
CWE-287
Improper Authentication
|
CVE-2009-4367
|
2018-10-11 04:49 |
2009-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287636
|
- |
|
bookingcentre
|
booking_system_for_hotels_group
|
SQL injection vulnerability in hotel_tiempolibre_ext.php in Venalsur Booking Centre Booking System for Hotels Group, when magic_quotes_gpc is enabled, allows remote attackers to execute arbitrary SQL…
|
CWE-89
SQL Injection
|
CVE-2009-4386
|
2018-10-11 04:49 |
2009-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287637
|
- |
|
sql-ledger
|
sql-ledger
|
The default configuration of SQL-Ledger 2.8.24 allows remote attackers to perform unspecified administrative operations by providing an arbitrary password to the admin interface.
|
CWE-16
Configuration
|
CVE-2009-4402
|
2018-10-11 04:49 |
2009-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287638
|
- |
|
rumbacms
|
rumba_xml
|
Cross-site scripting (XSS) vulnerability in index.php in Rumba XML 1.8 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO. NOTE: some of these details are obtained from…
|
CWE-79
Cross-site Scripting
|
CVE-2009-4403
|
2018-10-11 04:49 |
2009-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287639
|
- |
|
apc
|
ap7932_b2_firmware ap7932_b2
|
Cross-site scripting (XSS) vulnerability in Forms/login1 in American Power Conversion (APC) Switched Rack PDU AP7932 B2, running rpdu 3.3.3 or 3.7.0 on AOS 3.3.4, and possibly other versions, allows …
|
CWE-79
Cross-site Scripting
|
CVE-2009-4406
|
2018-10-11 04:49 |
2009-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287640
|
- |
|
pyforum
|
pyforum
|
Multiple cross-site request forgery (CSRF) vulnerabilities in PyForum 1.0.3 and possibly earlier versions, and possibly zForum, allow remote attackers to hijack the authentication of victims for requ…
|
CWE-352
Origin Validation Error
|
CVE-2009-4407
|
2018-10-11 04:49 |
2009-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|