Thinking OPEN

Contributor Archive

Audio %26 Video Library 2.7.0 [High]

By Security Team • Mar 18th, 2010 • Category: Security Notifications

SQL injection vulnerability in login.php in Allomani Audio & Video Library (Songs & Clips version) 2.7.0 allows remote attackers to execute arbitrary SQL commands via the username parameter in a login action….

CVE Identifier: CVE-2009-4735
Vulnerability Type(s):
Severity: High



Movie Library 2.7.0 [High]

By Security Team • Mar 18th, 2010 • Category: Security Notifications

SQL injection vulnerability in login.php in Allomani Movies Library (Movies & Clips) 2.7.0 allows remote attackers to execute arbitrary SQL commands via the username parameter in a login action….

CVE Identifier: CVE-2009-4734
Vulnerability Type(s):
Severity: High



Simpleloginsys 0.5 [Medium]

By Security Team • Mar 18th, 2010 • Category: Security Notifications

SQL injection vulnerability in checkuser.php in SimpleLoginSys 0.5, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the username parameter…

CVE Identifier: CVE-2009-4733
Vulnerability Type(s):
Severity: Medium



Tt Web Site Manager 0.5 [Medium]

By Security Team • Mar 18th, 2010 • Category: Security Notifications

SQL injection vulnerability in tt/index.php in TT Web Site Manager 0.5, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the tt_name parameter…

CVE Identifier: CVE-2009-4732
Vulnerability Type(s):
Severity: Medium



Model Agency Manager Pro [High]

By Security Team • Mar 18th, 2010 • Category: Security Notifications

SQL injection vulnerability in photos.php in Model Agency Manager PRO (formerly Modeling Agency Content Management Script) allows remote attackers to execute arbitrary SQL commands via the album parameter….

CVE Identifier: CVE-2009-4731
Vulnerability Type(s):
Severity: High



Adult Script 1.7 [High]

By Security Team • Mar 18th, 2010 • Category: Security Notifications

SQL injection vulnerability in report.php in x10 Adult Media Script 1.7 allows remote attackers to execute arbitrary SQL commands via the id parameter….

CVE Identifier: CVE-2009-4730
Vulnerability Type(s):
Severity: High



Adult Script 1.7 [Medium]

By Security Team • Mar 18th, 2010 • Category: Security Notifications

Multiple cross-site scripting (XSS) vulnerabilities in x10 Adult Media Script 1.7 allow remote attackers to inject arbitrary web script or HTML via the (1) pic_id parameter to includes/video_ad.php, (2) category parameter to linkvideos_listing.php, (3) id parameter to templates/header1.php, and (4) key parameter to video_listing.php….

CVE Identifier: CVE-2009-4729
Vulnerability Type(s):
Severity: Medium



Questions Answered 1.3 [High]

By Security Team • Mar 18th, 2010 • Category: Security Notifications

SQL injection vulnerability in the administrative interface in Questions Answered 1.3 allows remote attackers to execute arbitrary SQL commands via the username parameter…

CVE Identifier: CVE-2009-4728
Vulnerability Type(s):
Severity: High



Ajax Short Url Script [High]

By Security Team • Mar 18th, 2010 • Category: Security Notifications

SQL injection vulnerability in x/login in JungleScripts Ajax Short Url Script allows remote attackers to execute arbitrary SQL commands via the username parameter….

CVE Identifier: CVE-2009-4727
Vulnerability Type(s):
Severity: High



Quickdev4php [Medium]

By Security Team • Mar 18th, 2010 • Category: Security Notifications

Directory traversal vulnerability in download.php in Quickdev 4 PHP allows remote attackers to read arbitrary files via a ….

CVE Identifier: CVE-2009-4726
Vulnerability Type(s):
Severity: Medium