|
287921
|
- |
|
geekbill
|
open_biller
|
SQL injection vulnerability in index.php in Open Biller 0.1 allows remote attackers to execute arbitrary SQL commands via the username parameter.
|
CWE-89
SQL Injection
|
CVE-2009-2036
|
2018-10-11 04:39 |
2009-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287922
|
- |
|
zokisoft
|
zoki_catalog
|
SQL injection vulnerability in system/application/controllers/catalog.php in Zoki Soft Zoki Catalog (aka Smart Catalog) allows remote attackers to execute arbitrary SQL commands via the search_text p…
|
CWE-89
SQL Injection
|
CVE-2009-2097
|
2018-10-11 04:39 |
2009-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287923
|
- |
|
webmediaexplorer
|
webmedia_explorer
|
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Webmedia Explorer (webmex) 5.09 and 5.10 allow remote attackers to inject arbitrary web script or HTML via event handlers such as o…
|
CWE-79
Cross-site Scripting
|
CVE-2009-2107
|
2018-10-11 04:39 |
2009-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287924
|
- |
|
skybluecanvas
|
skybluecanvas
|
Multiple cross-site scripting (XSS) vulnerabilities in admin.php in SkyBlueCanvas 1.1 r237 allow remote attackers to inject arbitrary web script or HTML via the (1) mgroup, (2) mgr, (3) objtype, (4) …
|
CWE-79
Cross-site Scripting
|
CVE-2009-2114
|
2018-10-11 04:39 |
2009-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287925
|
- |
|
skybluecanvas
|
skybluecanvas
|
admin.php in SkyBlueCanvas 1.1 r237 allows remote authenticated administrators to obtain sensitive information via an invalid id parameter, which reveals the installation path in an error message.
|
CWE-200
Information Exposure
|
CVE-2009-2115
|
2018-10-11 04:39 |
2009-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287926
|
- |
|
skybluecanvas
|
skybluecanvas
|
Directory traversal vulnerability in admin.php in SkyBlueCanvas 1.1 r237 allows remote authenticated administrators to list directory contents via a .. (dot dot) in the dir parameter.
|
CWE-22
Path Traversal
|
CVE-2009-2116
|
2018-10-11 04:39 |
2009-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287927
|
- |
|
f5
|
firepass_ssl_vpn
|
Cross-site scripting (XSS) vulnerability in the login interface (my.logon.php3) in F5 FirePass SSL VPN 5.5 through 5.5.2 and 6.0 through 6.0.3 allows remote attackers to inject arbitrary web script o…
|
CWE-79
Cross-site Scripting
|
CVE-2009-2119
|
2018-10-11 04:39 |
2009-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287928
|
- |
|
pivot
|
pivot
|
Multiple cross-site scripting (XSS) vulnerabilities in Pivot 1.40.4 and 1.40.7 allow remote attackers to inject arbitrary web script or HTML via the (1) menu or (2) sort parameter to pivot/index.php,…
|
CWE-79
Cross-site Scripting
|
CVE-2009-2133
|
2018-10-11 04:39 |
2009-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287929
|
- |
|
pivot
|
pivot
|
pivot/tb.php in Pivot 1.40.4 and 1.40.7 allows remote attackers to obtain sensitive information via an invalid url parameter, which reveals the installation path in an error message.
|
CWE-200
Information Exposure
|
CVE-2009-2134
|
2018-10-11 04:39 |
2009-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287930
|
- |
|
torrenttrader
|
torrenttrader_classic
|
backup-database.php in TorrentTrader Classic 1.09 does not require administrative authentication, which allows remote attackers to create and download a backup database by making a direct request and…
|
CWE-287
Improper Authentication
|
CVE-2009-2159
|
2018-10-11 04:39 |
2009-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|