|
303561
|
- |
|
thomas_waggershauser
|
air_lexicon
|
SQL injection vulnerability in the AIRware Lexicon (air_lexicon) extension 0.0.1 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
|
CWE-89
SQL Injection
|
CVE-2009-4965
|
2024-11-21 10:10 |
2010-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303562
|
- |
|
ksplayer
|
ksp_sound_player
|
Stack-based buffer overflow in KSP 2006 FINAL allows remote attackers to execute arbitrary code via a long string in a .M3U playlist file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-4964
|
2024-11-21 10:10 |
2010-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303563
|
- |
|
typo3
|
commerce_extension
|
Cross-site scripting (XSS) vulnerability in the Commerce extension before 0.9.9 for TYPO3 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2009-4963
|
2024-11-21 10:10 |
2010-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303564
|
- |
|
adammo
|
fat_player
|
Stack-based buffer overflow in Fat Player 0.6b allows remote attackers to execute arbitrary code via a long string in a .wav file. NOTE: some of these details are obtained from third party informati…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-4962
|
2024-11-21 10:10 |
2010-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303565
|
- |
|
lanai-core
|
lanai-core
|
Lanai Core 0.6 allows remote attackers to obtain configuration information via a direct request to info.php, which calls the phpinfo function.
|
CWE-200
Information Exposure
|
CVE-2009-4961
|
2024-11-21 10:10 |
2010-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303566
|
- |
|
lanai-core
|
lanai-core
|
Directory traversal vulnerability in modules/backup/download.php in Lanai Core 0.6 allows remote attackers to read arbitrary files via a .. (dot dot) in the f parameter.
|
CWE-22
Path Traversal
|
CVE-2009-4960
|
2024-11-21 10:10 |
2010-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303567
|
- |
|
stefan_koch
|
t3m
|
SQL injection vulnerability in the T3M E-Mail Marketing Tool (t3m) extension 0.2.4 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
|
CWE-89
SQL Injection
|
CVE-2009-4959
|
2024-11-21 10:10 |
2010-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303568
|
- |
|
emophp
|
emo_breeder_manager
|
SQL injection vulnerability in video.php in EMO Breeder Manager (aka EMO Breader Manager) allows remote attackers to execute arbitrary SQL commands via the idd parameter.
|
CWE-89
SQL Injection
|
CVE-2009-4958
|
2024-11-21 10:10 |
2010-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303569
|
- |
|
interspire
|
activekb
|
Directory traversal vulnerability in loadpanel.php in Interspire ActiveKB allows remote attackers to read arbitrary files and possibly have unspecified other impact via directory traversal sequences …
|
CWE-22
Path Traversal
|
CVE-2009-4957
|
2024-11-21 10:10 |
2010-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303570
|
- |
|
wapplersystems
|
ws_stats
|
Cross-site scripting (XSS) vulnerability in the Visitor Tracking (ws_stats) extension before 0.1.2 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2009-4956
|
2024-11-21 10:10 |
2010-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|