|
292531
|
- |
|
opengoo
|
opengoo
|
Directory traversal vulnerability in upgrade/index.php in OpenGoo 1.1, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot…
|
CWE-22
Path Traversal
|
CVE-2009-0286
|
2017-09-29 10:33 |
2009-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292532
|
- |
|
sir
|
gnuboard
|
Directory traversal vulnerability in common.php in SIR GNUBoard 4.31.03 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the g4_path parameter. NOTE: in som…
|
CWE-22
Path Traversal
|
CVE-2009-0290
|
2017-09-29 10:33 |
2009-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292533
|
- |
|
shop-inet
|
shop-inet
|
SQL injection vulnerability in show_cat2.php in SHOP-INET 4 allows remote attackers to execute arbitrary SQL commands via the grid parameter.
|
CWE-89
SQL Injection
|
CVE-2009-0292
|
2017-09-29 10:33 |
2009-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292534
|
- |
|
wazzum
|
wazzum_dating_software
|
SQL injection vulnerability in profile_view.php in Wazzum Dating Software, possibly 2.0, allows remote attackers to execute arbitrary SQL commands via the userid parameter.
|
CWE-89
SQL Injection
|
CVE-2009-0293
|
2017-09-29 10:33 |
2009-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292535
|
- |
|
itlpoll
|
itpoll
|
SQL injection vulnerability in index.php in Information Technology Light Poll Information (ITLPoll) 2.7 Stable 2, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL c…
|
CWE-89
SQL Injection
|
CVE-2009-0295
|
2017-09-29 10:33 |
2009-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292536
|
- |
|
gempar
|
script_toko_online
|
SQL injection vulnerability in shop_display_products.php in Script Toko Online 5.01 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.
|
CWE-89
SQL Injection
|
CVE-2009-0296
|
2017-09-29 10:33 |
2009-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292537
|
- |
|
clicktech
|
clickauction
|
SQL injection vulnerability in login_check.asp in ClickAuction allows remote attackers to execute arbitrary SQL commands via the (1) txtEmail and (2) txtPassword parameters. NOTE: some of these deta…
|
CWE-89
SQL Injection
|
CVE-2009-0297
|
2017-09-29 10:33 |
2009-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292538
|
- |
|
mw6_technologies
|
barcode_activex
|
Heap-based buffer overflow in MW6 Technologies Barcode ActiveX control (Barcode.MW6Barcode.1, Barcode.dll) 3.0.0.1 allows remote attackers to execute arbitrary code via a long Supplement property.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-0298
|
2017-09-29 10:33 |
2009-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292539
|
- |
|
groonesworld
|
glinks
|
SQL injection vulnerability in index.php in Groone GLinks 2.1 allows remote attackers to execute arbitrary SQL commands via the cat parameter.
|
CWE-89
SQL Injection
|
CVE-2009-0299
|
2017-09-29 10:33 |
2009-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292540
|
- |
|
grid2000
|
flexcell_grid_control
|
Multiple insecure method vulnerabilities in the FlexCell.Grid ActiveX control (FlexCell.ocx) in FlexCell Grid Control 5.6.9 allow remote attackers to create and overwrite arbitrary files via the (1) …
|
NVD-CWE-Other
|
CVE-2009-0301
|
2017-09-29 10:33 |
2009-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|