| 47793 |
CVE-2009-0461 |
Whole Hog Password Protect: Enhanced 1.x allows remote attackers to bypass authentication and obtain administrative access via an integer value in the adminid cookie. |
|
2 |
7.5 |
High |
2017-01-07 |
2009-03-06 |
View
|
| 47794 |
CVE-2009-0462 |
Multiple SQL injection vulnerabilities in customer_login_check.asp in ClickTech ClickCart 6.0 allow remote attackers to execute arbitrary SQL commands via (1) the txtEmail parameter (aka E-MAIL field) or (2) the txtPassword parameter (aka password field) to customer_login.asp. NOTE: some of these details are obtained from third party information. |
|
2 |
7.5 |
High |
2017-01-07 |
2009-03-06 |
View
|
| 47796 |
CVE-2009-0464 |
PHP remote file inclusion vulnerability in includes/header.php in Groone GBook 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the abspath parameter. |
|
2 |
5.1 |
Medium |
2017-01-07 |
2009-03-06 |
View
|
| 47797 |
CVE-2009-0465 |
The SaveDoc method in the All_In_The_Box.AllBox ActiveX control in ALL_IN_THE_BOX.OCX in Synactis ALL In-The-Box ActiveX 3 allows remote attackers to create and overwrite arbitrary files via an argument ending in a " |