|
292461
|
- |
|
pardalcms
|
pardalcms
|
SQL injection vulnerability in comentar.php in Pardal CMS 0.2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2009-0279
|
2017-09-29 10:33 |
2009-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292462
|
- |
|
warhound
|
walking_club
|
SQL injection vulnerability in login.aspx in WarHound Walking Club allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.
|
CWE-89
SQL Injection
|
CVE-2009-0281
|
2017-09-29 10:33 |
2009-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292463
|
- |
|
opengoo
|
opengoo
|
Directory traversal vulnerability in upgrade/index.php in OpenGoo 1.1, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot…
|
CWE-22
Path Traversal
|
CVE-2009-0286
|
2017-09-29 10:33 |
2009-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292464
|
- |
|
sir
|
gnuboard
|
Directory traversal vulnerability in common.php in SIR GNUBoard 4.31.03 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the g4_path parameter. NOTE: in som…
|
CWE-22
Path Traversal
|
CVE-2009-0290
|
2017-09-29 10:33 |
2009-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292465
|
- |
|
shop-inet
|
shop-inet
|
SQL injection vulnerability in show_cat2.php in SHOP-INET 4 allows remote attackers to execute arbitrary SQL commands via the grid parameter.
|
CWE-89
SQL Injection
|
CVE-2009-0292
|
2017-09-29 10:33 |
2009-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292466
|
- |
|
wazzum
|
wazzum_dating_software
|
SQL injection vulnerability in profile_view.php in Wazzum Dating Software, possibly 2.0, allows remote attackers to execute arbitrary SQL commands via the userid parameter.
|
CWE-89
SQL Injection
|
CVE-2009-0293
|
2017-09-29 10:33 |
2009-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292467
|
- |
|
itlpoll
|
itpoll
|
SQL injection vulnerability in index.php in Information Technology Light Poll Information (ITLPoll) 2.7 Stable 2, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL c…
|
CWE-89
SQL Injection
|
CVE-2009-0295
|
2017-09-29 10:33 |
2009-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292468
|
- |
|
gempar
|
script_toko_online
|
SQL injection vulnerability in shop_display_products.php in Script Toko Online 5.01 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.
|
CWE-89
SQL Injection
|
CVE-2009-0296
|
2017-09-29 10:33 |
2009-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292469
|
- |
|
clicktech
|
clickauction
|
SQL injection vulnerability in login_check.asp in ClickAuction allows remote attackers to execute arbitrary SQL commands via the (1) txtEmail and (2) txtPassword parameters. NOTE: some of these deta…
|
CWE-89
SQL Injection
|
CVE-2009-0297
|
2017-09-29 10:33 |
2009-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292470
|
- |
|
mw6_technologies
|
barcode_activex
|
Heap-based buffer overflow in MW6 Technologies Barcode ActiveX control (Barcode.MW6Barcode.1, Barcode.dll) 3.0.0.1 allows remote attackers to execute arbitrary code via a long Supplement property.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-0298
|
2017-09-29 10:33 |
2009-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|