|
303591
|
- |
|
artifex
|
gpl_ghostscript afpl_ghostscript ghostscript_fonts
|
Buffer overflow in gs/psi/iscan.c in Ghostscript 8.64 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted PDF document contain…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-4897
|
2024-11-21 10:10 |
2010-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303592
|
- |
|
esoftpro
|
online_guestbook_pro
|
SQL injection vulnerability in ogp_show.php in Online Guestbook Pro allows remote attackers to execute arbitrary SQL commands via the display parameter.
|
CWE-89
SQL Injection
|
CVE-2009-4935
|
2024-11-21 10:10 |
2010-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303593
|
- |
|
esoftpro
|
online_photo_pro
|
Cross-site scripting (XSS) vulnerability in index.php in Online Photo Pro 2.0 allows remote attackers to inject arbitrary web script or HTML via the section parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2009-4934
|
2024-11-21 10:10 |
2010-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303594
|
- |
|
winterwebs
|
ezwebitor
|
Multiple SQL injection vulnerabilities in login.php in EZ Webitor allow remote attackers to execute arbitrary SQL commands via the (1) txtUserId (Username) and (2) txtPassword (Password) parameters. …
|
CWE-89
SQL Injection
|
CVE-2009-4933
|
2024-11-21 10:10 |
2010-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303595
|
- |
|
mpesch3.de1
|
1by1
|
Stack-based buffer overflow in 1by1 1.67 (aka 1.6.7.0) allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long string in a .m3u playlist…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-4932
|
2024-11-21 10:10 |
2010-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303596
|
- |
|
bestwebsharing
|
groovy_media_player
|
Stack-based buffer overflow in Groovy Media Player 1.1.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long string in a .m3u playli…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-4931
|
2024-11-21 10:10 |
2010-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303597
|
- |
|
sungard
|
banner_student
|
Cross-site scripting (XSS) vulnerability in the twbkwbis.P_SecurityQuestion (aka Change Security Question) page in SunGard Banner Student System 7.4 allows remote attackers to inject arbitrary web sc…
|
CWE-79
Cross-site Scripting
|
CVE-2009-4930
|
2024-11-21 10:10 |
2010-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303598
|
- |
|
sweetphp
|
totalcalender
|
admin/manage_users.php in TotalCalendar 2.4 does not require administrative authentication, which allows remote attackers to change arbitrary passwords via the newPW1 and newPW2 parameters.
|
CWE-287
Improper Authentication
|
CVE-2009-4929
|
2024-11-21 10:10 |
2010-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303599
|
- |
|
sweetphp
|
totalcalendar
|
PHP remote file inclusion vulnerability in config.php in TotalCalendar 2.4 allows remote attackers to execute arbitrary PHP code via a URL in the inc_dir parameter, a different vector than CVE-2006-1…
|
CWE-94
Code Injection
|
CVE-2009-4928
|
2024-11-21 10:10 |
2010-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303600
|
- |
|
webmobo
|
wbnews
|
WB News 2.1.2 allows remote attackers to bypass authentication and gain administrative access via a modified WBNEWS cookie, as demonstrated by setting this cookie to 1.
|
CWE-287
Improper Authentication
|
CVE-2009-4927
|
2024-11-21 10:10 |
2010-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|