|
303411
|
- |
|
php4scripte
|
gastebuch
|
Directory traversal vulnerability in gastbuch.php in Gästebuch (Gastebuch) 1.6 allows remote attackers to read arbitrary files via a .. (dot dot) in the start parameter.
|
CWE-22
Path Traversal
|
CVE-2009-5093
|
2024-11-21 10:11 |
2011-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303412
|
- |
|
microsoft
|
fast_esp
|
Cross-site scripting (XSS) vulnerability in the management interface in Microsoft FAST ESP 5.1.5 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2009-5092
|
2024-11-21 10:11 |
2011-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303413
|
- |
|
vlinks
|
vlinks
|
SQL injection vulnerability in page.php in Vlinks 1.0.3 and 1.1.6 allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2009-5091
|
2024-11-21 10:11 |
2011-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303414
|
- |
|
daman371
|
bloggeruniverse
|
SQL injection vulnerability in editcomments.php in Bloggeruniverse Beta 2, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter and possib…
|
CWE-89
SQL Injection
|
CVE-2009-5090
|
2024-11-21 10:11 |
2011-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303415
|
- |
|
ideacart
|
ideacart
|
Directory traversal vulnerability in index.php in IdeaCart 0.02 and 0.02a allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter.
|
CWE-22
Path Traversal
|
CVE-2009-5089
|
2024-11-21 10:11 |
2011-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303416
|
- |
|
ideacart
|
ideacart
|
SQL injection vulnerability in secure/index.php in IdeaCart 0.02 allows remote attackers to execute arbitrary SQL commands via the cID parameter.
|
CWE-89
SQL Injection
|
CVE-2009-5088
|
2024-11-21 10:11 |
2011-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303417
|
- |
|
geovision
|
digital_surveillance_system
|
Directory traversal vulnerability in geohttpserver in Geovision Digital Video Surveillance System 8.2 allows remote attackers to read arbitrary files via a .. (dot dot) in a GET request.
|
CWE-22
Path Traversal
|
CVE-2009-5087
|
2024-11-21 10:11 |
2011-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303418
|
- |
|
juniper
|
idp
|
Cross-site scripting (XSS) vulnerability in Appliance Configuration Manager (ACM) in Juniper IDP 4.1 before 4.1r3 and 4.2 before 4.2r1 allows remote attackers to inject arbitrary web script or HTML v…
|
CWE-79
Cross-site Scripting
|
CVE-2009-5086
|
2024-11-21 10:11 |
2011-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303419
|
- |
|
libpng
|
libpng
|
Memory leak in the embedded_profile_len function in pngwutil.c in libpng before 1.2.39beta5 allows context-dependent attackers to cause a denial of service (memory leak or segmentation fault) via a J…
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2009-5063
|
2024-11-21 10:11 |
2011-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303420
|
- |
|
ibm
|
tivoli_federated_identity_manager
|
IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.2, when configured as an OpenID provider, does not delete the site information cookie in response to a user's deletion of a relying-par…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-5085
|
2024-11-21 10:11 |
2011-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|