CVE-2009-4000 to CVE-2009-4999
473 CVEs with public proof-of-concept exploits.
- CVE-2009-40062 PoCsStack-based buffer overflow in the TEA decoding algorithm in RhinoSoft Serv-U FTP server 7.0.0.1, 9.0.0.5, and other versions before…
- CVE-2009-40171 PoCPHP before 5.2.12 and 5.3.x before 5.3.1 does not restrict the number of temporary files created when handling a multipart/form-data POST…
- CVE-2009-40181 PoCThe proc_open function in ext/standard/proc_open.c in PHP before 5.2.11 and 5.3.x before 5.3.1 does not enforce the (1)…
- CVE-2009-40192 PoCsmysqld in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41 does not (1) properly handle errors during execution of certain SELECT…
- CVE-2009-40322 PoCsMultiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.7e allow remote attackers to inject arbitrary web script or HTML via…
- CVE-2009-40391 PoCCross-site scripting (XSS) vulnerability in Piwigo before 2.0.6 allows remote attackers to inject arbitrary web script or HTML via…
- CVE-2009-40476 PoCsMultiple cross-site scripting (XSS) vulnerabilities in PHD Help Desk 1.43 allow remote attackers to inject arbitrary web script or HTML…
- CVE-2009-40482 PoCsDxmsoft XM Easy Personal FTP Server 5.8.0 allows remote authenticated users to cause a denial of service (daemon outage) via an APPE…
- CVE-2009-40492 PoCsHeap-based buffer overflow in aswRdr.sys (aka the TDI RDR driver) in avast! Home and Professional 4.8.1356.0 allows local users to cause a…
- CVE-2009-40501 PoCDirectory traversal vulnerability in get_file.php in phpMyBackupPro 2.1 allows remote attackers to read arbitrary files via directory…
- CVE-2009-40511 PoCHome FTP Server 1.10.1.139 allows remote attackers to cause a denial of service (daemon outage) via multiple invalid SITE INDEX commands.
- CVE-2009-40531 PoCMultiple directory traversal vulnerabilities in Home FTP Server 1.10.1.139 allow remote authenticated users to (1) create arbitrary…
- CVE-2009-40561 PoCDirectory traversal vulnerability in admin/popup.php in Betsy CMS 3.5 allows remote attackers to include and execute arbitrary local files…
- CVE-2009-40571 PoCSQL injection vulnerability in the inertialFATE iF Portfolio Nexus (com_if_nexus) component 1.1 for Joomla! allows remote attackers to…
- CVE-2009-40582 PoCsSQL injection vulnerability in allauctions.php in Telebid Auction Script allows remote attackers to execute arbitrary SQL commands via the…
- CVE-2009-40591 PoCSQL injection vulnerability in the JoomClip (com_joomclip) component for Joomla! allows remote attackers to execute arbitrary SQL commands…
- CVE-2009-40601 PoCSQL injection vulnerability in includes/content/viewProd.inc.php in CubeCart before 4.3.7 remote attackers to execute arbitrary SQL…
- CVE-2009-40671 PoCBuffer overflow in the auerswald_probe function in the Auerswald Linux USB driver for the Linux kernel before 2.6.27 allows physically…
- CVE-2009-40822 PoCsPHP remote file inclusion vulnerability in forums/Forum_Include/index.php in Outreach Project Tool (OPT) 1.2.7 and earlier allows remote…
- CVE-2009-40851 PoCPHP remote file inclusion vulnerability in assets/plugins/mp3_id/mp3_id.php in PHP Traverser 0.8.0 allows remote attackers to execute…
- CVE-2009-40861 PoCCRLF injection vulnerability in Xerver HTTP Server 4.31 and 4.32 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP…
- CVE-2009-40883 PoCsMultiple directory traversal vulnerabilities in telepark.wiki 2.4.23 and earlier allow remote attackers to read arbitrary files via…
- CVE-2009-40893 PoCstelepark.wiki 2.4.23 and earlier allows remote attackers to bypass authorization and (1) delete arbitrary pages via a modified pageID…
- CVE-2009-40913 PoCscomments.php in Simplog 0.9.3.2, and possibly earlier, does not properly restrict access, which allows remote attackers to edit or delete…
- CVE-2009-40924 PoCsCross-site request forgery (CSRF) vulnerability in user.php in Simplog 0.9.3.2, and possibly earlier, allows remote attackers to hijack…
- CVE-2009-40933 PoCsMultiple cross-site scripting (XSS) vulnerabilities in comments.php in Simplog 0.9.3.2, and possibly earlier, allow remote attackers to…
- CVE-2009-40941 PoCPHP remote file inclusion vulnerability in class/php/d4m_ajax_pagenav.php in the D4J eZine (com_ezine) component 2.1 for Joomla! allows…
- CVE-2009-40962 PoCsRADIO istek scripti 2.5 stores sensitive information under the web root with insufficient access control, which allows remote attackers to…
- CVE-2009-40972 PoCsStack-based buffer overflow in the MplayInputFile function in Serenity Audio Player 3.2.3 and earlier allows remote attackers to execute…
- CVE-2009-40982 PoCsUnrestricted file upload vulnerability in banner-edit.php in OpenX adserver 2.8.1 and earlier allows remote authenticated users with…
- CVE-2009-40991 PoCSQL injection vulnerability in the Google Calendar GCalendar (com_gcalendar) component 1.1.2, 2.1.4, and possibly earlier versions for…
- CVE-2009-41041 PoCSQL injection vulnerability in Lyften Designs LyftenBloggie (com_lyftenbloggie) component 1.0.4 for Joomla! allows remote attackers to…
- CVE-2009-41051 PoCTYPSoft FTP Server 1.10 allows remote authenticated users to cause a denial of service (crash) by sending an APPE (append) command…
- CVE-2009-41062 PoCsUnrestricted file upload vulnerability in admintools/editpage-2.php in Agoko CMS 0.4 and earlier allows remote attackers to inject and…
- CVE-2009-41072 PoCsBuffer overflow in Invisible Browsing 5.0.52 allows user-assisted remote attackers to execute arbitrary code via a crafted .ibkey file…
- CVE-2009-41082 PoCsXM Easy Personal FTP Server 5.8.0 allows remote authenticated users to cause a denial of service (crash) by uploading or creating a large…
- CVE-2009-41121 PoCCacti 0.8.7e and earlier allows remote authenticated administrators to gain privileges by modifying the "Data Input Method" for the "Linux…
- CVE-2009-41141 PoCkl1.sys in Kaspersky Anti-Virus 2010 9.0.0.463, and possibly other versions before 9.0.0.736, does not properly validate input to IOCTL…
- CVE-2009-41151 PoCMultiple static code injection vulnerabilities in the Categories module in CutePHP CuteNews 1.4.6 allow remote authenticated users with…
- CVE-2009-41171 PoCMultiple stack-based buffer overflows in pdf_shade4.c in MuPDF before commit 20091125231942, as used in SumatraPDF before 1.0.1, allow…
- CVE-2009-41182 PoCsThe StartServiceCtrlDispatcher function in the cvpnd service (cvpnd.exe) in Cisco VPN client for Windows before 5.0.06.0100 does not…
- CVE-2009-41202 PoCsMultiple cross-site request forgery (CSRF) vulnerabilities in Quick.Cart 3.4 allow remote attackers to hijack the authentication of the…
- CVE-2009-41311 PoCThe EXT4_IOC_MOVE_EXT (aka move extents) ioctl implementation in the ext4 filesystem in the Linux kernel before 2.6.32-git6 allows local…
- CVE-2009-41372 PoCsThe loadContentFromCookie function in core/Cookie.php in Piwik before 0.5 does not validate strings obtained from cookies before calling…
- CVE-2009-41409 PoCsUnrestricted file upload vulnerability in ofc_upload_image.php in Open Flash Chart v2 Beta 1 through v2 Lug Wyrm Charmer, as used in Piwik…
- CVE-2009-41411 PoCUse-after-free vulnerability in the fasync_helper function in fs/fcntl.c in the Linux kernel before 2.6.33-rc4-git1 allows local users to…
- CVE-2009-41422 PoCsThe htmlspecialchars function in PHP before 5.2.12 does not properly handle (1) overlong UTF-8 sequences, (2) invalid Shift_JIS sequences,…
- CVE-2009-41462 PoCsThe _rtld function in the Run-Time Link-Editor (rtld) in libexec/rtld-elf/rtld.c in FreeBSD 7.1, 7.2, and 8.0 does not clear the…
- CVE-2009-41472 PoCsThe _rtld function in the Run-Time Link-Editor (rtld) in libexec/rtld-elf/rtld.c in FreeBSD 7.1 and 8.0 does not clear the (1) LD_LIBMAP,…
- CVE-2009-41481 PoCDAZ Studio 2.3.3.161, 2.3.3.163, and 3.0.1.135 allows remote attackers to execute arbitrary JavaScript code via a (1) .ds, (2) .dsa, (3)…
- CVE-2009-41541 PoCDirectory traversal vulnerability in includes/feedcreator.class.php in Elxis CMS allows remote attackers to read arbitrary files via a ..…
- CVE-2009-41551 PoCMultiple SQL injection vulnerabilities in Eshopbuilde CMS allow remote attackers to execute arbitrary SQL commands via the sitebid…
- CVE-2009-41562 PoCsPHP remote file inclusion vulnerability in modules/pms/index.php in Ciamos CMS 0.9.5 and earlier allows remote attackers to execute…
- CVE-2009-41571 PoCMultiple cross-site scripting (XSS) vulnerabilities in index.php in the ProofReader (com_proofreader) component 1.0 RC9 and earlier for…
- CVE-2009-41681 PoCCross-site scripting (XSS) vulnerability in Roy Tanck tagcloud.swf, as used in the WP-Cumulus plugin before 1.23 for WordPress and the…
- CVE-2009-41701 PoCWP-Cumulus Plug-in 1.20 for WordPress, and possibly other versions, allows remote attackers to obtain sensitive information via a crafted…
- CVE-2009-41712 PoCsAn ActiveX control in YahooBridgeLib.dll for Yahoo! Messenger 9.0.0.2162, and possibly other 9.0 versions, allows remote attackers to…
- CVE-2009-41722 PoCsCross-site scripting (XSS) vulnerability in index.php in CutePHP CuteNews 1.4.6 and UTF-8 CuteNews 8 and 8b, when magic_quotes_gpc is…
- CVE-2009-41732 PoCsCross-site request forgery (CSRF) vulnerability in CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b allows remote attackers to hijack…
- CVE-2009-41741 PoCThe editnews module in CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b, when magic_quotes_gpc is disabled, allows remote authenticated…
- CVE-2009-41752 PoCsCutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b allows remote attackers to obtain sensitive information via an invalid date value in…
- CVE-2009-41783 PoCsHeap-based buffer overflow in OvWebHelp.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to…
- CVE-2009-41793 PoCsStack-based buffer overflow in ovalarm.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to…
- CVE-2009-41862 PoCsStack consumption vulnerability in Apple Safari 4.0.3 on Windows allows remote attackers to cause a denial of service (application crash)…
- CVE-2009-41883 PoCsHP Operations Dashboard has a default password of j2deployer for the j2deployer account, which allows remote attackers to execute…
- CVE-2009-41892 PoCsHP Operations Manager has a default password of OvW*busr1 for the ovwebusr account, which allows remote attackers to execute arbitrary…
- CVE-2009-41921 PoCDirectory traversal vulnerability in dialog/file_manager.php in Interspire Knowledge Manager 5 allows remote attackers to read arbitrary…
- CVE-2009-41942 PoCsDirectory traversal vulnerability in Golden FTP Server 4.30 Free and Professional, 4.50, and possibly other versions allows remote…
- CVE-2009-41955 PoCsBuffer overflow in Adobe Illustrator CS4 14.0.0, CS3 13.0.3 and earlier, and CS3 13.0.0 allows remote attackers to execute arbitrary code…
- CVE-2009-41962 PoCsMultiple cross-site scripting (XSS) vulnerabilities in multiple scripts in Forms/ in Huawei MT882 V100R002B020 ARG-T running firmware…
- CVE-2009-41972 PoCsrpwizPppoe.htm in Huawei MT882 V100R002B020 ARG-T running firmware 3.7.9.98 contains a form that does not disable the autocomplete setting…
- CVE-2009-41982 PoCsSQL injection vulnerability in my_orders.php in MyMiniBill allows remote authenticated users to execute arbitrary SQL commands via the…
- CVE-2009-41992 PoCsMultiple SQL injection vulnerabilities in the Mambo Resident (aka Mos Res or com_mosres) component 1.0f for Mambo and Joomla!, when…
- CVE-2009-42002 PoCsSQL injection vulnerability in the Seminar (com_seminar) component 1.28 for Joomla! allows remote attackers to execute arbitrary SQL…
- CVE-2009-42023 PoCsDirectory traversal vulnerability in the Omilen Photo Gallery (com_omphotogallery) component Beta 0.5 for Joomla! allows remote attackers…
- CVE-2009-42032 PoCsMultiple SQL injection vulnerabilities in admin/aclass/admin_func.php in Arab Portal 2.2 allow remote attackers to execute arbitrary SQL…
- CVE-2009-42042 PoCsSQL injection vulnerability in read.php in Flashlight Free Edition allows remote attackers to execute arbitrary SQL commands via the id…
- CVE-2009-42052 PoCsDirectory traversal vulnerability in admin.php in Flashlight Free Edition allows remote attackers to include and execute arbitrary local…
- CVE-2009-42062 PoCsSQL injection vulnerability in admin.link.modify.php in Million Dollar Text Links 1.0 and earlier allows remote attackers to execute…
- CVE-2009-42082 PoCsSQL injection vulnerability in the os_news module in Open-school (OS) 1.0 allows remote attackers to execute arbitrary SQL commands via…
- CVE-2009-42091 PoCMultiple cross-site scripting (XSS) vulnerabilities in admin/index.php in moziloCMS 1.11.1 allow remote attackers to inject arbitrary web…
- CVE-2009-42161 PoCDirectory traversal vulnerability in funzioni/lib/menulast.php in klinza professional cms 5.0.1 and earlier allows remote attackers to…
- CVE-2009-42171 PoCSQL injection vulnerability in the Itamar Elharar MusicGallery (com_musicgallery) component for Joomla! allows remote attackers to execute…
- CVE-2009-42181 PoCMultiple SQL injection vulnerabilities in files/login.asp in JiRo's Banner System eXperience (JBSX) allow remote attackers to execute…
- CVE-2009-42191 PoCStack-based buffer overflow in the MYACTIVEX.MyActiveXCtrl.1 ActiveX control in MyActiveX.ocx 1.4.8.0 in Haihaisoft Universal Player…
- CVE-2009-42202 PoCsPHP remote file inclusion vulnerability in includes/classes/pctemplate.php in PointComma 3.8b2 and earlier allows remote attackers to…
- CVE-2009-42212 PoCsSQL injection vulnerability in classified.php in phpBazar 2.1.1fix and earlier allows remote attackers to execute arbitrary SQL commands…
- CVE-2009-42221 PoCphpBazar 2.1.1fix and earlier does not require administrative authentication for admin/admin.php, which allows remote attackers to obtain…
- CVE-2009-42233 PoCsPHP remote file inclusion vulnerability in adm/krgourl.php in KR-Web 1.1b2 and earlier allows remote attackers to execute arbitrary PHP…
- CVE-2009-42242 PoCsMultiple PHP remote file inclusion vulnerabilities in SweetRice 0.5.4, 0.5.3, and earlier allow remote attackers to execute arbitrary PHP…
- CVE-2009-42252 PoCsStack-based buffer overflow in the PestPatrol ActiveX control (ppctl.dll) 5.6.7.9 in CA eTrust PestPatrol allows remote attackers to…
- CVE-2009-42271 PoCStack-based buffer overflow in the read_1_3_textobject function in f_readold.c in Xfig 3.2.5b and earlier, and in the read_textobject…
- CVE-2009-42291 PoCMultiple SQL injection vulnerabilities in ActiveWebSoftwares Active Bids allow remote attackers to execute arbitrary SQL commands via (1)…
- CVE-2009-42311 PoCDirectory traversal vulnerability in as/lib/plugins.php in SweetRice 0.5.3 and earlier allows remote attackers to include and execute…
- CVE-2009-42341 PoCCross-site scripting (XSS) vulnerability in loginpages/error_user.shtml on the Micronet Network Access Controller SP1910 allows remote…
- CVE-2009-42371 PoCMultiple cross-site scripting (XSS) vulnerabilities in TestLink before 1.8.5 allow remote attackers to inject arbitrary web script or HTML…
- CVE-2009-42381 PoCMultiple SQL injection vulnerabilities in TestLink before 1.8.5 allow remote authenticated users to execute arbitrary SQL commands via (1)…
- CVE-2009-42492 PoCsMultiple cross-site scripting (XSS) vulnerabilities in CutePHP CuteNews 1.4.6, when register_globals is enabled and magic_quotes_gpc is…
- CVE-2009-42502 PoCsMultiple cross-site scripting (XSS) vulnerabilities in CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b allow remote attackers to…
- CVE-2009-42511 PoCStack-based buffer overflow in Jasc Paint Shop Pro 8.10 (aka Corel Paint Shop Pro) allows user-assisted remote attackers to execute…
- CVE-2009-42521 PoCCross-site scripting (XSS) vulnerability in images.php in Image Hosting Script DPI 1.1 Final (1.1F) allows remote attackers to inject…
- CVE-2009-42531 PoCCross-site scripting (XSS) vulnerability in dspStats.php in PowerPhlogger 2.2.5 allows remote attackers to inject arbitrary web script or…
- CVE-2009-42551 PoCCross-site scripting (XSS) vulnerability in the You!Hostit! template 1.0.1 for Joomla! allows remote attackers to inject arbitrary web…
- CVE-2009-42562 PoCsMultiple SQL injection vulnerabilities in cource.php in AlefMentor 2.0 and 2.2 allow remote attackers to execute arbitrary SQL commands…
- CVE-2009-42632 PoCsSQL injection vulnerability in main_forum.php in PTCPay GeN3 forum 1.3 allows remote attackers to execute arbitrary SQL commands via the…
- CVE-2009-42642 PoCsPHP remote file inclusion vulnerability in components/core/connect.php in AROUNDMe 1.1 and earlier, when register_globals is enabled,…
- CVE-2009-42654 PoCsStack-based buffer overflow in Ideal Administration 2009 9.7.1, and possibly other versions, allows remote attackers to execute arbitrary…
- CVE-2009-42662 PoCsCross-site scripting (XSS) vulnerability in search.php in YABSoft Advanced Image Hosting (AIH) Script 2.2, and possibly 2.3, allows remote…
- CVE-2009-42731 PoCstap-server in SystemTap before 1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in stap command-line…
- CVE-2009-43151 PoCDirectory traversal vulnerability in admin/ajaxsave.php in Nuggetz CMS 1.0, when magic_quotes_gpc is disabled, allows remote attackers to…
- CVE-2009-43171 PoCCross-site scripting (XSS) vulnerability in index.php in ScriptsEz Ez Cart allows remote attackers to inject arbitrary web script or HTML…
- CVE-2009-43181 PoCCross-site scripting (XSS) vulnerability in index.php in Real Estate Manager 1.0.1 allows remote attackers to inject arbitrary web script…
- CVE-2009-43192 PoCsPHP remote file inclusion vulnerability in js/bbcodepress/bbcode-form.php in eoCMS 0.9.03 and earlier, when register_globals is enabled,…
- CVE-2009-43201 PoCCross-site scripting (XSS) vulnerability in searchform.php in The Next Generation of Genealogy Sitebuilding (TNG) 7.1.2 allows remote…
- CVE-2009-43245 PoCsKEVUse-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x…
- CVE-2009-43481 PoCCross-site scripting (XSS) vulnerability in index.php in Harold Bakker's NewsScript (HB-NS) 1.3 allows remote attackers to inject…
- CVE-2009-43492 PoCsCross-site request forgery (CSRF) vulnerability in administration/administrators.php in Link Up Gold 5.0 allows remote attackers to hijack…
- CVE-2009-43512 PoCsSQL injection vulnerability in ADMIN/loginaction.php in WSCreator 1.1, when magic_quotes_gpc is disabled, allows remote attackers to…
- CVE-2009-43591 PoCCross-site scripting (XSS) vulnerability in folder.php in the SmartMedia 0.85 Beta module for XOOPS allows remote attackers to inject…
- CVE-2009-43601 PoCSQL injection vulnerability in modules/content/index.php in the Content module 0.5 for XOOPS allows remote attackers to inject arbitrary…
- CVE-2009-43642 PoCsCross-site scripting (XSS) vulnerability in index.php in ScriptsEz Ez Blog allows remote attackers to inject arbitrary web script or HTML…
- CVE-2009-43652 PoCsMultiple cross-site request forgery (CSRF) vulnerabilities in admin.php in ScriptsEz Ez Blog 1.0 allow remote attackers to hijack the…
- CVE-2009-43662 PoCsCross-site scripting (XSS) vulnerability in index.php in ScriptsEz Ez Blog 1.0 allows remote attackers to inject arbitrary web script or…
- CVE-2009-43672 PoCsThe Staging Webservice ("sitecore modules/staging/service/api.asmx") in Sitecore Staging Module 5.4.0 rev.080625 and earlier allows remote…
- CVE-2009-43691 PoCCross-site scripting (XSS) vulnerability in the Contact module (modules/contact/contact.admin.inc or modules/contact/contact.module) in…
- CVE-2009-43711 PoCCross-site scripting (XSS) vulnerability in the Locale module (modules/locale/locale.module) in Drupal Core 6.14, and possibly other…
- CVE-2009-43722 PoCsAlienVault Open Source Security Information Management (OSSIM) 2.1.5, and possibly other versions before 2.1.5-4, allows remote attackers…
- CVE-2009-43751 PoCSQL injection vulnerability in repository/repository_attachment.php in AlienVault Open Source Security Information Management (OSSIM)…
- CVE-2009-43812 PoCsCross-site scripting (XSS) vulnerability in index.php in texmedia Million Pixel Script 3 allows remote attackers to inject arbitrary web…
- CVE-2009-43822 PoCsCross-site scripting (XSS) vulnerability in module.php in PHPFABER CMS, possibly 1.3.36, allows remote attackers to inject arbitrary web…
- CVE-2009-43842 PoCsMultiple cross-site scripting (XSS) vulnerabilities in Scriptsez.net Ez Poll Hoster (EPH) allow remote attackers to inject arbitrary web…
- CVE-2009-43852 PoCsMultiple cross-site request forgery (CSRF) vulnerabilities in Scriptsez.net Ez Poll Hoster (EPH) allow remote attackers to (1) hijack the…
- CVE-2009-43862 PoCsSQL injection vulnerability in hotel_tiempolibre_ext.php in Venalsur Booking Centre Booking System for Hotels Group, when magic_quotes_gpc…
- CVE-2009-44032 PoCsCross-site scripting (XSS) vulnerability in index.php in Rumba XML 1.8 allows remote attackers to inject arbitrary web script or HTML via…
- CVE-2009-44132 PoCsThe httpClientDiscardBody function in client.c in Polipo 0.9.8, 0.9.12, 1.0.4, and possibly other versions, allows remote attackers to…
- CVE-2009-44181 PoCThe unserialize function in PHP 5.3.0 and earlier allows context-dependent attackers to cause a denial of service (resource consumption)…
- CVE-2009-44211 PoCDirectory traversal vulnerability in languages_cgi.php in Simple PHP Blog 0.5.1 and earlier allows remote authenticated users to include…
- CVE-2009-44232 PoCsSQL injection vulnerability in index.php in weenCompany 4.0.0 allows remote attackers to execute arbitrary SQL commands via the moduleid…
- CVE-2009-44242 PoCsSQL injection vulnerability in results.php in the Pyrmont plugin 2 for WordPress allows remote attackers to execute arbitrary SQL commands…
- CVE-2009-44251 PoCCross-site scripting (XSS) vulnerability in index.php in iDevCart 1.09 allows remote attackers to inject arbitrary web script or HTML via…
- CVE-2009-44262 PoCsMultiple directory traversal vulnerabilities in Ignition 1.2, when magic_quotes_gpc is disabled, allow remote attackers to include and…
- CVE-2009-44272 PoCsDirectory traversal vulnerability in cmd.php in phpLDAPadmin 1.1.0.5 allows remote attackers to include and execute arbitrary local files…
- CVE-2009-44281 PoCSQL injection vulnerability in the JoomPortfolio (com_joomportfolio) component 1.0.0 for Joomla! allows remote attackers to execute…
- CVE-2009-44292 PoCsCross-site scripting (XSS) vulnerability in the Sections module 5.x before 5.x-1.3 and 6.x before 6.x-1.3 for Drupal allows remote…
- CVE-2009-44302 PoCsSQL injection vulnerability in index.php in VirtueMart 1.0 allows remote attackers to execute arbitrary SQL commands via the product_id…
- CVE-2009-44311 PoCPHP remote file inclusion vulnerability in cal_popup.php in the Anything Digital Development JCal Pro (aka com_jcalpro or JCP) component…
- CVE-2009-44322 PoCsSQL injection vulnerability in index.php in CodeMight VideoCMS 3.1 allows remote attackers to execute arbitrary SQL commands via the v…
- CVE-2009-44334 PoCsMultiple cross-site scripting (XSS) vulnerabilities in IDevSpot iSupport 1.8 and earlier allow remote attackers to inject arbitrary web…
- CVE-2009-44342 PoCsDirectory traversal vulnerability in index.php in IDevSpot iSupport 1.8 and earlier allows remote attackers to read arbitrary files via a…
- CVE-2009-44353 PoCsMultiple directory traversal vulnerabilities in F3Site 2009 allow remote attackers to include and execute arbitrary local files via…
- CVE-2009-44362 PoCsMultiple SQL injection vulnerabilities in Active Web Softwares eWebquiz 8 allow remote attackers to execute arbitrary SQL commands via the…
- CVE-2009-44372 PoCsMultiple SQL injection vulnerabilities in Active Auction House 3.6 allow remote attackers to execute arbitrary SQL commands via the (1)…
- CVE-2009-44462 PoCsCross-site scripting (XSS) vulnerability in admin.php in phpInstantGallery 1.1 allows remote attackers to inject arbitrary web script or…
- CVE-2009-44472 PoCsJax Guestbook 3.5.0 allows remote attackers to bypass authentication and modify administrator settings via a direct request to…
- CVE-2009-44501 PoCMultiple cross-site scripting (XSS) vulnerabilities in map.php in LiveZilla 3.1.8.3 allow remote attackers to inject arbitrary web script…
- CVE-2009-44512 PoCsUnrestricted file upload vulnerability in upper.php in kandalf upper 0.1 allows remote attackers to execute arbitrary code by uploading a…
- CVE-2009-44522 PoCsKaspersky Anti-Virus 5.0 (5.0.712); Antivirus Personal 5.0.x; Anti-Virus 6.0 (6.0.3.837), 7 (7.0.1.325), 2009 (8.0.0.x), and 2010…
- CVE-2009-44532 PoCsInsecure method vulnerability in SoftCab Sound Converter ActiveX control (sndConverter.ocx) 1.2 allows remote attackers to create or…
- CVE-2009-44541 PoCvccleaner in VideoCache 1.9.2 allows local users with Squid proxy user privileges to overwrite arbitrary files via a symlink attack on…
- CVE-2009-44562 PoCsSQL injection vulnerability in news_detail.php in Green Desktiny 2.3.1, and possibly earlier versions, allows remote attackers to execute…
- CVE-2009-44584 PoCsMultiple cross-site scripting (XSS) vulnerabilities in FreePBX 2.5.2 and 2.6.0rc2, and possibly other versions, allow remote attackers to…
- CVE-2009-44591 PoCRedmine 0.8.7 and earlier uses the title tag before defining the character encoding in a meta tag, which allows remote attackers to…
- CVE-2009-44601 PoCMultiple cross-site scripting (XSS) vulnerabilities in Auto-Surf Traffic Exchange Script 1.1 allow remote attackers to inject arbitrary…
- CVE-2009-44612 PoCsMultiple cross-site scripting (XSS) vulnerabilities in FlatPress 0.909 allow remote attackers to inject arbitrary web script or HTML via…
- CVE-2009-44622 PoCsStack-based buffer overflow in the NetBiterConfig utility (NetBiterConfig.exe) 1.3.0 for Intellicom NetBiter WebSCADA allows remote…
- CVE-2009-44641 PoCCross-site scripting (XSS) vulnerability in searchadvance.asp in Active Business Directory 2 allows remote attackers to inject arbitrary…
- CVE-2009-44652 PoCsDeluxeBB 1.3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain…
- CVE-2009-44662 PoCsDeluxeBB 1.3 allows remote attackers to obtain sensitive information via a crafted page parameter to misc.php, which reveals the…
- CVE-2009-44672 PoCsmisc.php in DeluxeBB 1.3 allows remote attackers to register accounts without a valid email address via a valemail action with the valmem…
- CVE-2009-44682 PoCsCross-site scripting (XSS) vulnerability in misc.php in DeluxeBB 1.3 allows remote attackers to inject arbitrary web script or HTML via…
- CVE-2009-44692 PoCsMultiple cross-site scripting (XSS) vulnerabilities in pagenumber.inc.php in phpPowerCards 2.0 allow remote attackers to inject arbitrary…
- CVE-2009-44701 PoCSQL injection vulnerability in boardrule.php in DVBBS 2.0 allows remote attackers to execute arbitrary SQL commands via the groupboardid…
- CVE-2009-44712 PoCsMultiple PHP remote file inclusion vulnerabilities in FreeSchool 1.1.0 and earlier allow remote attackers to execute arbitrary PHP code…
- CVE-2009-44722 PoCsMultiple PHP remote file inclusion vulnerabilities in PHPope 1.0.0 and earlier allow remote attackers to execute arbitrary PHP code via a…
- CVE-2009-44742 PoCsSQL injection vulnerability in the Mike de Boer zoom (com_zoom) component 2.0 for Mambo allows remote attackers to execute arbitrary SQL…
- CVE-2009-44752 PoCsSQL injection vulnerability in the Joomlub (com_joomlub) component for Joomla! allows remote attackers to execute arbitrary SQL commands…
- CVE-2009-44772 PoCsSQL injection vulnerability in page.html in Xstate Real Estate 1.0 allows remote attackers to execute arbitrary SQL commands via the pid…
- CVE-2009-44782 PoCsMultiple cross-site scripting (XSS) vulnerabilities in Xstate Real Estate 1.0 allow remote attackers to inject arbitrary web script or…
- CVE-2009-44844 PoCsMultiple stack-based buffer overflows in the CertDecoder::GetName function in src/asn.cpp in TaoCrypt in yaSSL before 1.9.9, as used in…
- CVE-2009-44872 PoCsnginx 0.7.64 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a…
- CVE-2009-44881 PoCVarnish 2.0.6 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a…
- CVE-2009-44891 PoCheader.c in Cherokee before 0.99.32 writes data to a log file without sanitizing non-printable characters, which might allow remote…
- CVE-2009-44901 PoCmini_httpd 1.19 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a…
- CVE-2009-44911 PoCthttpd 2.25b0 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a…
- CVE-2009-44921 PoCWEBrick 1.3.1 in Ruby 1.8.6 through patchlevel 383, 1.8.7 through patchlevel 248, 1.8.8dev, 1.9.1 through patchlevel 376, and 1.9.2dev…
- CVE-2009-44931 PoCOrion Application Server 2.0.7 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers…
- CVE-2009-44941 PoCAOLserver 4.5.1 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a…
- CVE-2009-44951 PoCYaws 1.85 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's…
- CVE-2009-44961 PoCBoa 0.94.14rc21 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a…
- CVE-2009-44971 PoCCross-site scripting (XSS) vulnerability in LXR Cross Referencer 0.9.5 and 0.9.6 allows remote attackers to inject arbitrary web script or…
- CVE-2009-44983 PoCsThe node_process_command function in Zabbix Server before 1.8 allows remote attackers to execute arbitrary commands via a crafted request.
- CVE-2009-44991 PoCSQL injection vulnerability in the get_history_lastid function in the nodewatcher component in Zabbix Server before 1.6.8 allows remote…
- CVE-2009-45011 PoCThe zbx_get_next_field function in libs/zbxcommon/str.c in Zabbix Server before 1.6.8 allows remote attackers to cause a denial of service…
- CVE-2009-45023 PoCsThe NET_TCP_LISTEN function in net.c in Zabbix Agent before 1.6.7, when running on FreeBSD or Solaris, allows remote attackers to bypass…
- CVE-2009-45111 PoCMultiple directory traversal vulnerabilities in the web administration interface on the TANDBERG Video Communication Server (VCS) before…
- CVE-2009-45121 PoCDirectory traversal vulnerability in index.php in Oscailt 3.3, when Use Friendly URL's is disabled, allows remote attackers to include and…
- CVE-2009-45211 PoCCross-site scripting (XSS) vulnerability in birt-viewer/run in Eclipse Business Intelligence and Reporting Tools (BIRT) before 2.5.0, as…
- CVE-2009-45221 PoCCross-site scripting (XSS) vulnerability in search.5.html in BloofoxCMS 0.3.5 allows remote attackers to inject arbitrary web script or…
- CVE-2009-45231 PoCCross-site scripting (XSS) vulnerability in index.php in Zainu 1.0 allows remote attackers to inject arbitrary web script or HTML via the…
- CVE-2009-45311 PoChttpdx 1.4.4 and earlier allows remote attackers to obtain the source code for a web page by appending a . (dot) character to the URI.
- CVE-2009-45352 PoCsMongoose 2.8.0 and earlier allows remote attackers to obtain the source code for a web page by appending a / (slash) character to the URI.
- CVE-2009-45402 PoCsSQL injection vulnerability in page.php in Mini CMS 1.0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.
- CVE-2009-45412 PoCsMultiple PHP remote file inclusion vulnerabilities in IsolSoft Support Center 2.5 allow remote attackers to execute arbitrary PHP code via…
- CVE-2009-45422 PoCsCross-site scripting (XSS) vulnerability in newticket.php in IsolSoft Support Center 2.5 allows remote attackers to inject arbitrary web…
- CVE-2009-45432 PoCsPHP remote file inclusion vulnerability in index.php in Cromosoft Technologies Facil Helpdesk 2.3 Lite allows remote attackers to execute…
- CVE-2009-45443 PoCsCross-site scripting (XSS) vulnerability in kbase/kbase.php in Cromosoft Technologies Facil Helpdesk 2.3 Lite allows remote attackers to…
- CVE-2009-45452 PoCsLogoshows BBS 2.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to…
- CVE-2009-45462 PoCsglobepersonnel_login.asp in Logoshows BBS 2.0 allows remote attackers to bypass authentication and gain administrative access by setting…
- CVE-2009-45473 PoCsMultiple cross-site scripting (XSS) vulnerabilities in ViArt CMS 3.x allow remote attackers to inject arbitrary web script or HTML via the…
- CVE-2009-45486 PoCsMultiple cross-site scripting (XSS) vulnerabilities in ViArt Helpdesk 3.x allow remote attackers to inject arbitrary web script or HTML…
- CVE-2009-45492 PoCsStack-based buffer overflow in A2 Media Player Pro 2.51 allows remote attackers to execute arbitrary code via a long string in a (1) .m3u…
- CVE-2009-45502 PoCsSQL injection vulnerability in the Kunena Forum (com_kunena) component 1.5.3 and 1.5.4 for Joomla! allows remote attackers to execute…
- CVE-2009-45512 PoCsSQL injection vulnerability in the Survey Pro module for Miniweb 2.0 allows remote attackers to execute arbitrary SQL commands via the…
- CVE-2009-45522 PoCsCross-site scripting (XSS) vulnerability in the Survey Pro module for Miniweb 2.0 allows remote attackers to inject arbitrary web script…
- CVE-2009-45532 PoCsStack-based buffer overflow in iRehearse allows remote attackers to cause a denial of service (application crash) or possibly have…
- CVE-2009-45543 PoCsMultiple cross-site scripting (XSS) vulnerabilities in Snitz Forums 2000 3.4.07 allow remote attackers to inject arbitrary web script or…
- CVE-2009-45561 PoCQuick Heal AntiVirus Plus 2009 10.00 SP1 and Quick Heal Total Security 2009 10.00 SP1 use weak permissions (Everyone: Full Control) for…
- CVE-2009-45602 PoCsSQL injection vulnerability in profile.php in WebLeague 2.2.0 allows remote attackers to execute arbitrary SQL commands via the name…
- CVE-2009-45612 PoCsMultiple SQL injection vulnerabilities in Admin/index.php in WebLeague 2.2.0, when magic_quotes_gpc is disabled, allow remote attackers to…
- CVE-2009-45622 PoCsCross-site scripting (XSS) vulnerability in zp-core/admin.php in Zenphoto 1.2.5 allows remote attackers to inject arbitrary web script or…
- CVE-2009-45632 PoCsCross-site request forgery (CSRF) vulnerability in zp-core/admin-options.php in Zenphoto 1.2.5 allows remote attackers to hijack the…
- CVE-2009-45642 PoCsSQL injection vulnerability in index.php in Zenphoto 1.2.5, when the ZenPage plugin is enabled, allows remote attackers to execute…
- CVE-2009-45661 PoCSQL injection vulnerability in index.php in Zenphoto 1.2.5 allows remote attackers to execute arbitrary SQL commands via the title…
- CVE-2009-45672 PoCsMultiple cross-site scripting (XSS) vulnerabilities in editprofile.php in Viscacha 0.8 Gold allow remote authenticated users to inject…
- CVE-2009-45692 PoCsSQL injection vulnerability in elkagroup Image Gallery allows remote attackers to execute arbitrary SQL commands via the id parameter to…
- CVE-2009-45712 PoCsMultiple SQL injection vulnerabilities in index.php in PhpShop 0.8.1 allow remote attackers to execute arbitrary SQL commands via the (1)…
- CVE-2009-45742 PoCsSQL injection vulnerability in country_escorts.php in I-Escorts Directory Script allows remote attackers to execute arbitrary SQL commands…
- CVE-2009-45752 PoCsCross-site scripting (XSS) vulnerability in the Q-Personel (com_qpersonel) component 1.0.2 RC2 for Joomla! allows remote attackers to…
- CVE-2009-45762 PoCsSQL injection vulnerability in the BeeHeard (com_beeheard) component 1.x for Joomla! allows remote attackers to execute arbitrary SQL…
- CVE-2009-45782 PoCsCross-site scripting (XSS) vulnerability in the Facileforms (com_facileforms) component for Joomla! and Mambo allows remote attackers to…
- CVE-2009-45791 PoCCross-site scripting (XSS) vulnerability in the Artist avenue (com_artistavenue) component for Joomla! and Mambo allows remote attackers…
- CVE-2009-45801 PoCMultiple cross-site scripting (XSS) vulnerabilities in Hasta Blog 2.3 allow remote attackers to inject arbitrary web script or HTML via…
- CVE-2009-45812 PoCsDirectory traversal vulnerability in modules/admincp.php in RoseOnlineCMS 3 B1 and earlier, when magic_quotes_gpc is disabled, allows…
- CVE-2009-45822 PoCsSQL injection vulnerability in detail.php in the Dictionary module for XOOPS 2.0.18 allows remote attackers to execute arbitrary SQL…
- CVE-2009-45832 PoCsSQL injection vulnerability in the DhForum (com_dhforum) component for Joomla! allows remote attackers to execute arbitrary SQL commands…
- CVE-2009-45852 PoCsUranyumSoft Listing Service stores sensitive information under the web root with insufficient access control, which allows remote…
- CVE-2009-45871 PoCCherokee Web Server 0.5.4 allows remote attackers to cause a denial of service (daemon crash) via an MS-DOS reserved word in a URI, as…
- CVE-2009-45884 PoCsHeap-based buffer overflow in the WindsPlayerIE.View.1 ActiveX control in WindsPly.ocx 3.5.0.0 Beta, 3.0.0.5, and earlier in AwingSoft…
- CVE-2009-45951 PoCSQL injection vulnerability in index.php in PHP Inventory 1.2 allows remote authenticated users to execute arbitrary SQL commands via the…
- CVE-2009-45962 PoCsCross-site scripting (XSS) vulnerability in index.php in PHP Inventory 1.2 allows remote attackers to inject arbitrary web script or HTML…
- CVE-2009-45972 PoCsMultiple SQL injection vulnerabilities in index.php in PHP Inventory 1.2 allow (1) remote authenticated users to execute arbitrary SQL…
- CVE-2009-45982 PoCsSQL injection vulnerability in the JPhoto (com_jphoto) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands…
- CVE-2009-45993 PoCsMultiple SQL injection vulnerabilities in the JS Jobs (com_jsjobs) component 1.0.5.6 for Joomla! allow remote attackers to execute…
- CVE-2009-46002 PoCsSQL injection vulnerability in realestate20/loginaction.php in NetArt Media Real Estate Portal 2.0 allows remote attackers to execute…
- CVE-2009-46011 PoCCross-site scripting (XSS) vulnerability in basic_search_result.php in Zeeways ZeeJobsite 3x allows remote attackers to inject arbitrary…
- CVE-2009-46042 PoCsPHP remote file inclusion vulnerability in mamboleto.php in the Fernando Soares Mamboleto (com_mamboleto) component 2.0 RC3 for Joomla!…
- CVE-2009-46061 PoCSouth River Technologies WebDrive 9.02 build 2232 installs the WebDrive Service without a security descriptor, which allows local users to…
- CVE-2009-46071 PoCThe command line interface in Overland Storage Snap Server 410 with GuardianOS 5.1.041 runs the "less" utility with a higher-privileged…
- CVE-2009-46101 PoCMultiple cross-site scripting (XSS) vulnerabilities in Mort Bay Jetty 6.x and 7.0.0 allow remote attackers to inject arbitrary web script…
- CVE-2009-46121 PoCMultiple cross-site scripting (XSS) vulnerabilities in the WebApp JSP Snoop page in Mort Bay Jetty 6.1.x through 6.1.21 allow remote…
- CVE-2009-46131 PoCSQL injection vulnerability in realestate20/loginaction.php in NetArt Media Real Estate Portal 2.0 allows remote attackers to execute…
- CVE-2009-46142 PoCsMultiple PHP remote file inclusion vulnerabilities in Moa Gallery 1.2.0 and earlier allow remote attackers to execute arbitrary PHP code…
- CVE-2009-46152 PoCsSQL injection vulnerability in review.php in MYRE Holiday Rental Manager allows remote attackers to execute arbitrary SQL commands via the…
- CVE-2009-46162 PoCsCross-site scripting (XSS) vulnerability in search.php in MYRE Holiday Rental Manager allows remote attackers to inject arbitrary web…
- CVE-2009-46172 PoCsMultiple SQL injection vulnerabilities in Tourism Script Accommodation Hotel Booking Portal Script allow remote attackers to execute…
- CVE-2009-46182 PoCsMultiple SQL injection vulnerabilities in Tourism Script Bus Script allow remote attackers to execute arbitrary SQL commands via the…
- CVE-2009-46191 PoCSQL injection vulnerability in the Lucy Games (com_lucygames) component 1.5.4 for Joomla! allows remote attackers to execute arbitrary SQL…
- CVE-2009-46202 PoCsSQL injection vulnerability in the Joomloc (com_joomloc) component 1.0 for Joomla allows remote attackers to execute arbitrary SQL…
- CVE-2009-46212 PoCsSQL injection vulnerability in the JiangHu Inn plugin 1.1 and earlier for Discuz! allows remote attackers to execute arbitrary SQL…
- CVE-2009-46222 PoCsPHP remote file inclusion vulnerability in admin/admin_news_bot.php in Drunken:Golem Gaming Portal 0.5.1 alpha 2 allows remote attackers…
- CVE-2009-46236 PoCsMultiple PHP remote file inclusion vulnerabilities in Advanced Comment System 1.0 allow remote attackers to execute arbitrary PHP code via…
- CVE-2009-46242 PoCsSQL injection vulnerability in download.php in Nicecoder iDesk allows remote attackers to execute arbitrary SQL commands via the cat_id…
- CVE-2009-46252 PoCsSQL injection vulnerability in the updateOnePage function in components/com_bfsurvey_pro/controller.php in BF Survey Pro Free…
- CVE-2009-46262 PoCsDirectory traversal vulnerability in menu.php in phpNagios 1.2.0 allows remote attackers to include and execute arbitrary local files via…
- CVE-2009-46272 PoCsDirectory traversal vulnerability in sources/_template_parser.php in Moa Gallery 1.2.0 and earlier allows remote attackers to read…
- CVE-2009-46282 PoCsSQL injection vulnerability in the TemplatePlaza.com TPDugg (com_tpdugg) component 1.1 for Joomla! allows remote attackers to execute…
- CVE-2009-46371 PoCFFmpeg 0.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors that…
- CVE-2009-46451 PoCDirectory traversal vulnerability in web_client_user_guide.html in Accellion Secure File Transfer Appliance before 8_0_105 allows remote…
- CVE-2009-46481 PoCAccellion Secure File Transfer Appliance before 8_0_105 does not properly restrict access to sensitive commands and arguments that run…
- CVE-2009-46501 PoCSQL injection vulnerability in the Webee Comments (com_webeecomment) component 1.1.1, 1.2, and 2.0 for Joomla! allows remote attackers to…
- CVE-2009-46511 PoCMultiple cross-site scripting (XSS) vulnerabilities in the Webee Comments (com_webeecomment) component 1.1.1, 1.2, and 2.0 for Joomla!…
- CVE-2009-46531 PoCStack-based buffer overflow in the dhost module in Novell eDirectory 8.8 SP5 for Windows allows remote authenticated users to cause a…
- CVE-2009-46541 PoCStack-based buffer overflow in the dhost module in Novell eDirectory 8.8 SP5 for Windows allows remote authenticated users to execute…
- CVE-2009-46552 PoCsThe dhost web service in Novell eDirectory 8.8.5 uses a predictable session cookie, which makes it easier for remote attackers to hijack…
- CVE-2009-46566 PoCsStack-based buffer overflow in E-Soft DJ Studio Pro 4.2 including 4.2.2.7.5, and 5.x including 5.1.4.3.1, allows user-assisted remote…
- CVE-2009-46572 PoCsThe administrator package for Xerver 4.32 does not require authentication, which allows remote attackers to alter application settings by…
- CVE-2009-46582 PoCsXerver 4.32 allows remote authenticated users to cause a denial of service (daemon crash) via a non-numeric web port assignment in the…
- CVE-2009-46592 PoCsUnspecified vulnerability in MP3-Cutter Ease Audio Cutter 1.20 allows user-assisted remote attackers to cause a denial of service…
- CVE-2009-46606 PoCsStack-based buffer overflow in the AntServer Module (AntServer.exe) in BigAnt IM Server 2.50 allows remote attackers to execute arbitrary…
- CVE-2009-46614 PoCsMultiple buffer overflows in BigAnt Server 2.50 SP6 and earlier allow user-assisted remote attackers to cause a denial of service…
- CVE-2009-46633 PoCsHeap-based buffer overflow in the Quiksoft EasyMail Objects 6 ActiveX control allows remote attackers to execute arbitrary code via a long…
- CVE-2009-46652 PoCsDirectory traversal vulnerability in CuteSoft_Client/CuteEditor/Load.ashx in CuteSoft Components Cute Editor for ASP.NET allows remote…
- CVE-2009-46662 PoCsMultiple PHP remote file inclusion vulnerabilities in Webradev Download Protect 1.0 allow remote attackers to execute arbitrary PHP code…
- CVE-2009-46672 PoCsSQL injection vulnerability in form.php in WebMember 1.0 allows remote authenticated users to execute arbitrary SQL commands via the…
- CVE-2009-46683 PoCsStack-based buffer overflow in JetCast.exe 2.0.4.1109 in jetAudio 7.5.2 and 7.5.3.15 allows remote attackers to execute arbitrary code via…
- CVE-2009-46692 PoCsMultiple SQL injection vulnerabilities in RoomPHPlanning 1.6 allow remote attackers to execute arbitrary SQL commands via (1) the loginus…
- CVE-2009-46702 PoCsadmin/delitem.php in RoomPHPlanning 1.6 does not require authentication, which allows remote attackers to (1) delete arbitrary users via…
- CVE-2009-46712 PoCsLogin.php in RoomPHPlanning 1.6 allows remote attackers to bypass authentication and obtain administrative access by setting the…
- CVE-2009-46722 PoCsDirectory traversal vulnerability in main.php in the WP-Lytebox plugin 1.3 for WordPress allows remote attackers to include and execute…
- CVE-2009-46732 PoCsSQL injection vulnerability in profile.php in Mole Group Adult Portal Script allows remote attackers to execute arbitrary SQL commands via…
- CVE-2009-46742 PoCsadmin/admin.php in Mole Group Sky Hunter Airline Ticket Sale Script and Bus Ticket Script allows remote attackers to change an arbitrary…
- CVE-2009-46752 PoCsadmin/admin_info/index.php in the Mole Group Gastro Portal (Restaurant Directory) Script does not require administrative authentication,…
- CVE-2009-46761 PoCStack-based buffer overflow in JetCast.exe 2.0.4.1109 in jetAudio 7.5.2 and 7.5.3.15 allows remote attackers to execute arbitrary code via…
- CVE-2009-46782 PoCsCross-site scripting (XSS) vulnerability in index.php in Winn Guestbook 2.4 allows remote attackers to inject arbitrary web script or HTML…
- CVE-2009-46794 PoCsDirectory traversal vulnerability in the inertialFATE iF Portfolio Nexus (com_if_nexus) component 1.5 for Joomla! allows remote attackers…
- CVE-2009-46802 PoCsSQL injection vulnerability in search.php in phpDirectorySource 1.x allows remote attackers to execute arbitrary SQL commands via the st…
- CVE-2009-46812 PoCsCross-site scripting (XSS) vulnerability in search.php in phpDirectorySource 1.x allows remote attackers to inject arbitrary web script or…
- CVE-2009-46822 PoCsCross-site scripting (XSS) vulnerability in vote.php in Good/Bad Vote allows remote attackers to inject arbitrary web script or HTML via…
- CVE-2009-46832 PoCsDirectory traversal vulnerability in vote.php in Good/Bad Vote allows remote attackers to include and execute arbitrary local files via…
- CVE-2009-46841 PoCCross-site scripting (XSS) vulnerability in index.php in EZodiak allows remote attackers to inject arbitrary web script or HTML via the…
- CVE-2009-46851 PoCCross-site scripting (XSS) vulnerability in celebrities.php in PHP Scripts Now Astrology allows remote attackers to inject arbitrary web…
- CVE-2009-46861 PoCCross-site scripting (XSS) vulnerability in account.php in phplemon AdQuick 2.2.1 allows remote attackers to inject arbitrary web script…
- CVE-2009-46872 PoCsSQL injection vulnerability in silentum_guestbook.php in Silentum Guestbook 2.0.2 allows remote attackers to execute arbitrary SQL…
- CVE-2009-46881 PoCMultiple cross-site scripting (XSS) vulnerabilities in index.php in PHP Shopping Cart Selling Website Script allow remote attackers to…
- CVE-2009-46891 PoCSQL injection vulnerability in index.php in PHP Shopping Cart Selling Website Script allows remote attackers to execute arbitrary SQL…
- CVE-2009-46902 PoCsMultiple cross-site scripting (XSS) vulnerabilities in YourFreeWorld Programs Rating Script allow remote attackers to inject arbitrary web…
- CVE-2009-46911 PoCSQL injection vulnerability in addlink.php in Classified Linktrader Script allows remote attackers to execute arbitrary SQL commands via…
- CVE-2009-46922 PoCsCross-site scripting (XSS) vulnerability in index.php in RadScripts RadLance Gold 7.5 allows remote attackers to inject arbitrary web…
- CVE-2009-46932 PoCsMultiple PHP remote file inclusion vulnerabilities in GraFX MiniCWB 2.3.0 allow remote attackers to execute arbitrary PHP code via a URL…
- CVE-2009-46941 PoCCross-site scripting (XSS) vulnerability in index.php in RadScripts RadLance Gold 7.5 allows remote attackers to inject arbitrary web…
- CVE-2009-46952 PoCsSQL injection vulnerability in index.php in RadScripts RadLance Gold 7.5 allows remote attackers to execute arbitrary SQL commands via the…
- CVE-2009-46962 PoCsSQL injection vulnerability in index.php in RadNICS Gold 5 allows remote attackers to execute arbitrary SQL commands via the fid parameter…
- CVE-2009-46972 PoCsMultiple cross-site scripting (XSS) vulnerabilities in index.php in RadNICS Gold 5 allow remote attackers to inject arbitrary web script…
- CVE-2009-46984 PoCsMultiple SQL injection vulnerabilities in the Qas (aka Quas) module for XOOPS Celepar allow remote attackers to execute arbitrary SQL…
- CVE-2009-46992 PoCsMultiple cross-site scripting (XSS) vulnerabilities in SkaDate Dating allow remote attackers to inject arbitrary web script or HTML via…
- CVE-2009-47002 PoCsDirectory traversal vulnerability in index.php in SkaDate Dating allows remote attackers to read arbitrary files via a .. (dot dot) in the…
- CVE-2009-47132 PoCsMultiple cross-site scripting (XSS) vulnerabilities in the Qas (aka Quas) module for XOOPS Celepar allow remote attackers to inject…
- CVE-2009-47141 PoCCross-site scripting (XSS) vulnerability in the quiz module for XOOPS Celepar allows remote attackers to inject arbitrary web script or…
- CVE-2009-47176 PoCsMultiple cross-site scripting (XSS) vulnerabilities in Gonafish WebStatCaffe allow remote attackers to inject arbitrary web script or HTML…
- CVE-2009-47192 PoCsSQL injection vulnerability in index.php in Discloser 0.0.4 rc2 allows remote attackers to execute arbitrary SQL commands via the more…
- CVE-2009-47212 PoCsMultiple SQL injection vulnerabilities in Admin/index.asp in Andrews-Web (A-W) BannerAd 1.0 allow remote attackers to execute arbitrary…
- CVE-2009-47222 PoCsSQL injection vulnerability in the CheckLogin function in includes/functions.php in Limny 1.01, when magic_quotes_gpc is disabled, allows…
- CVE-2009-47232 PoCsDirectory traversal vulnerability in confirm.php in Netpet CMS 1.9 allows remote attackers to include and execute arbitrary local files…
- CVE-2009-47243 PoCsSQL injection vulnerability in shop.htm in PaymentProcessorScript.net PPScript allows remote attackers to execute arbitrary SQL commands…
- CVE-2009-47252 PoCsDirectory traversal vulnerability in modules/aljazeera/admin/setup.php in Arab Portal 2.2 and earlier, when register_globals is enabled…
- CVE-2009-47262 PoCsDirectory traversal vulnerability in download.php in Quickdev 4 PHP allows remote attackers to read arbitrary files via a .. (dot dot) in…
- CVE-2009-47272 PoCsSQL injection vulnerability in x/login in JungleScripts Ajax Short Url Script allows remote attackers to execute arbitrary SQL commands…
- CVE-2009-47282 PoCsSQL injection vulnerability in the administrative interface in Questions Answered 1.3 allows remote attackers to execute arbitrary SQL…
- CVE-2009-47292 PoCsMultiple cross-site scripting (XSS) vulnerabilities in x10 Adult Media Script 1.7 allow remote attackers to inject arbitrary web script or…
- CVE-2009-47302 PoCsSQL injection vulnerability in report.php in x10 Adult Media Script 1.7 allows remote attackers to execute arbitrary SQL commands via the…
- CVE-2009-47322 PoCsSQL injection vulnerability in tt/index.php in TT Web Site Manager 0.5, when magic_quotes_gpc is disabled, allows remote attackers to…
- CVE-2009-47332 PoCsSQL injection vulnerability in checkuser.php in SimpleLoginSys 0.5, when magic_quotes_gpc is disabled, allows remote attackers to execute…
- CVE-2009-47342 PoCsSQL injection vulnerability in login.php in Allomani Movies Library (Movies & Clips) 2.7.0 allows remote attackers to execute arbitrary…
- CVE-2009-47352 PoCsSQL injection vulnerability in login.php in Allomani Audio & Video Library (Songs & Clips version) 2.7.0 allows remote attackers to…
- CVE-2009-47361 PoCCross-site scripting (XSS) vulnerability in search.php in CommonSense CMS 5.0 allows remote attackers to inject arbitrary web script or…
- CVE-2009-47392 PoCsPHP remote file inclusion vulnerability in index.php in SkaDate Dating allows remote attackers to execute arbitrary PHP code via a URL in…
- CVE-2009-47421 PoCMultiple SQL injection vulnerabilities in Docebo 3.6.0.3 allow remote attackers to execute arbitrary SQL commands via (1) the word…
- CVE-2009-47432 PoCsMultiple cross-site scripting (XSS) vulnerabilities in history-storage.aspx in AfterLogic WebMail Pro 4.7.10 and earlier allow remote…
- CVE-2009-47452 PoCsMultiple SQL injection vulnerabilities in index.php in Dreamlevels DreamPoll 3.1 allow remote attackers to execute arbitrary SQL commands…
- CVE-2009-47461 PoCCross-site scripting (XSS) vulnerability in index.php in Dreamlevels DreamPoll 3.1 allows remote attackers to inject arbitrary web script…
- CVE-2009-47471 PoCPHP remote file inclusion vulnerability in public/code/cp_html2xhtmlbasic.php in All In One Control Panel (AIOCP) 1.4.001 allows remote…
- CVE-2009-47482 PoCsSQL injection vulnerability in mycategoryorder.php in the My Category Order plugin 2.8 and earlier for WordPress allows remote attackers…
- CVE-2009-47492 PoCsMultiple SQL injection vulnerabilities in PHP Live! 3.2.1 and 3.2.2 allow remote attackers to execute arbitrary SQL commands via the x…
- CVE-2009-47501 PoCPHP remote file inclusion vulnerability in home.php in Top Paidmailer allows remote attackers to execute arbitrary PHP code via a URL in…
- CVE-2009-47511 PoCSQL injection vulnerability in anzeiger/start.php in Swinger Club Portal allows remote attackers to execute arbitrary SQL commands via the…
- CVE-2009-47521 PoCPHP remote file inclusion vulnerability in anzeiger/start.php in Swinger Club Portal allows remote attackers to execute arbitrary PHP code…
- CVE-2009-47532 PoCsMultiple buffer overflows in the FTP server on the Addonics NAS Adapter NASU2FW41 with loader 1.17 allow remote attackers to cause a…
- CVE-2009-47544 PoCsStack-based buffer overflow in Mercury Audio Player 1.21 allows remote attackers to execute arbitrary code via a long string in a…
- CVE-2009-47553 PoCsMultiple stack-based buffer overflows in Mercury Audio Player 1.21 allow remote attackers to execute arbitrary code via a long string in a…
- CVE-2009-47568 PoCsStack-based buffer overflow in TraktorBeatport.exe 1.0.0.283 in Beatport Player 1.0.0.0 allows remote attackers to execute arbitrary code…
- CVE-2009-47572 PoCsStack-based buffer overflow in BrotherSoft EW-MusicPlayer 0.8 allows remote attackers to cause a denial of service (application crash) or…
- CVE-2009-47582 PoCsStack-based buffer overflow in dicas Mpegable Player 2.12 allows remote attackers to cause a denial of service (application crash) or…
- CVE-2009-47592 PoCsBuffer overflow in BrotherSoft BMXPlay 0.4.4b allows remote attackers to cause a denial of service (application crash) or possibly execute…
- CVE-2009-47602 PoCsWinn ASP Guestbook 1.01 Beta stores sensitive information under the web root with insufficient access control, which allows remote…
- CVE-2009-47613 PoCsStack-based buffer overflow in Mini-stream RM Downloader allows remote attackers to execute arbitrary code via a long string in a .smi file.
- CVE-2009-47672 PoCsMultiple cross-site scripting (XSS) vulnerabilities in index.php in Plohni Shoutbox 1.0 allow remote attackers to inject arbitrary web…
- CVE-2009-47693 PoCsMultiple format string vulnerabilities in the tolog function in httpdx 1.4, 1.4.5, 1.4.6, 1.4.6b, and 1.5 allow (1) remote attackers to…
- CVE-2009-47752 PoCsFormat string vulnerability in Ipswitch WS_FTP Professional 12 before 12.2 allows remote attackers to cause a denial of service (crash)…
- CVE-2009-47792 PoCsMultiple PHP remote file inclusion vulnerabilities in NukeHall 0.3 and earlier allow remote attackers to execute arbitrary PHP code via a…
- CVE-2009-47801 PoCMultiple cross-site scripting (XSS) vulnerabilities in index.php in phpMyFAQ before 2.5.5 allow remote attackers to inject arbitrary web…
- CVE-2009-47812 PoCsTUKEVA Password Reminder before 1.0.0.4 uses a hard-coded password for rem.accdb, which allows local users to discover credentials via a…
- CVE-2009-47821 PoCMultiple cross-site scripting (XSS) vulnerabilities in Theeta CMS, possibly 0.01, allow remote attackers to inject arbitrary web script or…
- CVE-2009-47831 PoCMultiple SQL injection vulnerabilities in Theeta CMS, possibly 0.01, allow remote attackers to execute arbitrary SQL commands via the…
- CVE-2009-47841 PoCSQL injection vulnerability in the Joaktree (com_joaktree) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL…
- CVE-2009-47851 PoCSQL injection vulnerability in the Quick News (com_quicknews) component for Joomla! allows remote attackers to execute arbitrary SQL…
- CVE-2009-47891 PoCMultiple PHP remote file inclusion vulnerabilities in the MojoBlog component RC 0.15 for Joomla! allow remote attackers to execute…
- CVE-2009-47901 PoCMultiple directory traversal vulnerabilities in Sysax Multi Server 4.5 allow remote authenticated users to read or modify arbitrary files…
- CVE-2009-47912 PoCsMultiple SQL injection vulnerabilities in Family Connections (aka FCMS) before 1.8.2 allow remote attackers to execute arbitrary SQL…
- CVE-2009-47922 PoCsSQL injection vulnerability in includes/content/member_content.php in BandSite CMS 1.1.4 allows remote attackers to execute arbitrary SQL…
- CVE-2009-47932 PoCsUnrestricted file upload vulnerability in adminpanel/scripts/addphotos.php in BandSite CMS 1.1.4 allows remote authenticated…
- CVE-2009-47941 PoCMultiple SQL injection vulnerabilities in Community CMS 0.5 allow remote attackers to execute arbitrary SQL commands via the (1)…
- CVE-2009-47951 PoCMultiple SQL injection vulnerabilities in Xlight FTP Server before 3.2.1, when ODBC authentication is enabled, allow remote attackers to…
- CVE-2009-47963 PoCsMultiple SQL injection vulnerabilities in the ExecuteQueries function in private/system/classes/listfactory.class.php in glFusion 1.1.2…
- CVE-2009-47972 PoCsSQL injection vulnerability in browse.php in JobHut 1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the pk…
- CVE-2009-47982 PoCsMultiple SQL injection vulnerabilities in Diskos CMS 6.x allow remote attackers to execute arbitrary SQL commands via the (1) kat…
- CVE-2009-47992 PoCsDiskos CMS 6.x stores sensitive information under the web root with insufficient access control, which allows remote attackers to download…
- CVE-2009-48002 PoCsDirectory traversal vulnerability in Sysax Multi Server 4.3 and 4.5 allows remote authenticated users to delete arbitrary files via a ..//…
- CVE-2009-48012 PoCsEZ-Blog Beta 1 does not require authentication, which allows remote attackers to create or delete arbitrary posts via requests to PHP…
- CVE-2009-48052 PoCsMultiple SQL injection vulnerabilities in EZ-Blog Beta 1, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary…
- CVE-2009-48062 PoCsadmin/save_user.asp in Digital Interchange Document Library 1.0.1 does not require administrative authentication, which allows remote…
- CVE-2009-48072 PoCsMultiple SQL injection vulnerabilities in Graugon PHP Article Publisher 1.0 allow remote attackers to execute arbitrary SQL commands via…
- CVE-2009-48083 PoCsadmin.php in Graugon PHP Article Publisher 1.0 allows remote attackers to bypass authentication and obtain administrative access by…
- CVE-2009-48092 PoCsDirectory traversal vulnerability in thumbnail.ghp in Easy File Sharing (EFS) Web Server 4.8 allows remote attackers to read arbitrary…
- CVE-2009-48111 PoCVMware Authentication Daemon 1.0 in vmware-authd.exe in the VMware Authorization Service in VMware Workstation 7.0 before 7.0.1 build…
- CVE-2009-48132 PoCsCross-site scripting (XSS) vulnerability in myps.php in MyBB (aka MyBulletinBoard) 1.4.10 allows remote attackers to inject arbitrary web…
- CVE-2009-48141 PoCCross-site scripting (XSS) vulnerability in Wolfram Research webMathematica allows remote attackers to inject arbitrary web script or HTML…
- CVE-2009-48162 PoCsDirectory traversal vulnerability in api/download_checker.php in MegaLab The Uploader 2.0 allows remote attackers to read arbitrary files…
- CVE-2009-48172 PoCsUnrestricted file upload vulnerability in Element-IT Ultimate Uploader 1.3 allows remote attackers to execute arbitrary code by uploading…
- CVE-2009-48182 PoCsUnrestricted file upload vulnerability in upload.php in PHPSimplicity Simplicity oF Upload 1.3.2 allows remote attackers to execute…
- CVE-2009-48192 PoCsMultiple unrestricted file upload vulnerabilities in upload.php in PHPhotoalbum allow remote attackers to execute arbitrary code by…
- CVE-2009-48202 PoCsAngelo-Emlak 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to…
- CVE-2009-48211 PoCThe D-Link DIR-615 with firmware 3.10NA does not require administrative authentication for apply.cgi, which allows remote attackers to (1)…
- CVE-2009-48223 PoCsMultiple cross-site scripting (XSS) vulnerabilities in index.php in Kasseler CMS 1.3.4 allow remote attackers to inject arbitrary web…
- CVE-2009-48232 PoCsCross-site scripting (XSS) vulnerability in frontend/x3/files/fileop.html in cPanel 11.0 through 11.24.7 allows remote attackers to inject…
- CVE-2009-48252 PoCs8pixel.net Blog 4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to…
- CVE-2009-48262 PoCsCross-site request forgery (CSRF) vulnerability in hosting/admin_ac.php in ScriptsEz Mini Hosting Panel allows remote attackers to hijack…
- CVE-2009-48272 PoCsCross-site request forgery (CSRF) vulnerability in admin.php in Mail Manager Pro allows remote attackers to hijack the authentication of…
- CVE-2009-48282 PoCsCross-site request forgery (CSRF) vulnerability in administration/admins.php in Ad Manager Pro (aka AdManagerPro) 3.0 allows remote…
- CVE-2009-48322 PoCsThe dlpcrypt.sys kernel driver 0.1.1.27 in DESlock+ 4.0.2 allows local users to gain privileges via a crafted IOCTL 0x80012010 request to…
- CVE-2009-48342 PoCslib.php in Zeroboard 4.1 pl7 allows remote attackers to execute arbitrary PHP code via a crafted parameter name, possibly related to…
- CVE-2009-48362 PoCsEval injection vulnerability in system/services/init.php in Movie PHP Script 2.0 allows remote attackers to execute arbitrary PHP code via…
- CVE-2009-48402 PoCsHeap-based buffer overflow in the IAManager ActiveX control in IAManager.dll in Roxio CinePlayer 3.2 allows remote attackers to execute…
- CVE-2009-48412 PoCsHeap-based buffer overflow in the SonicMediaPlayer ActiveX control in SonicMediaPlayer.dll in Roxio CinePlayer 3.2 allows remote attackers…
- CVE-2009-48491 PoCMultiple cross-site request forgery (CSRF) vulnerabilities in ToutVirtual VirtualIQ Pro 3.2 build 7882 and 3.5 build 8691 allow remote…
- CVE-2009-48503 PoCsThe Awingsoft Awakening Winds3D Viewer plugin 3.5.0.9 allows remote attackers to execute arbitrary programs via a SceneURL property value…
- CVE-2009-48542 PoCsaddons/import.php in TalkBack 2.3.14 allows remote attackers to execute arbitrary commands via the result parameter.
- CVE-2009-48553 PoCsSQL injection vulnerability in index.php in TYPO3 4.0 allows remote attackers to execute arbitrary SQL commands via the showUid parameter.…
- CVE-2009-48561 PoCCross-site scripting (XSS) vulnerability in subitems.php in PHP Easy Shopping Cart 3.1R allows remote attackers to inject arbitrary web…
- CVE-2009-48571 PoCCross-site scripting (XSS) vulnerability in login.php in PHP Photo Vote 1.3F allows remote attackers to inject arbitrary web script or…
- CVE-2009-48581 PoCCross-site scripting (XSS) vulnerability in questiondetail.php in Yahoo Answers Clone allows remote attackers to inject arbitrary web…
- CVE-2009-48602 PoCsSQL injection vulnerability in demo.php in Typing Pal 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the…
- CVE-2009-48622 PoCsMultiple SQL injection vulnerabilities in Alwasel 1.5 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1)…
- CVE-2009-48632 PoCsStack-based buffer overflow in UltraPlayer Media Player 2.112 allows remote attackers to execute arbitrary code via a long string in a…
- CVE-2009-48641 PoCMultiple cross-site scripting (XSS) vulnerabilities in escorts_search.php in I-Escorts Directory Script and Agency Script allow remote…
- CVE-2009-48672 PoCsBuffer overflow in Tuniac 090517c allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary…
- CVE-2009-48681 PoCCross-site scripting (XSS) vulnerability in Hitron Soft Answer Me 1.0 allows remote attackers to inject arbitrary web script or HTML via…
- CVE-2009-48691 PoCCross-site scripting (XSS) vulnerability in index.php in Nasim Guest Book 1.2 allows remote attackers to inject arbitrary web script or…
- CVE-2009-48702 PoCsMultiple SQL injection vulnerabilities in login.php in PHPCityPortal allow remote attackers to execute arbitrary SQL commands via the (1)…
- CVE-2009-48712 PoCsSQL injection vulnerability in globepersonnel_forum.asp in Logoshows BBS 2.0 allows remote attackers to execute arbitrary SQL commands via…
- CVE-2009-48722 PoCsMultiple SQL injection vulnerabilities in globepersonnel_login.asp in Logoshows BBS 2.0 allow remote attackers to execute arbitrary SQL…
- CVE-2009-48732 PoCsStack-based buffer overflow in the HTTP server in Rhino Software Serv-U Web Client 9.0.0.5 allows remote attackers to cause a denial of…
- CVE-2009-48742 PoCsTalkBack 2.3.14 does not properly restrict access to the edit comment feature (comments.php), which allows remote attackers to modify…
- CVE-2009-48762 PoCsadmin/cikkform.php in Netrix CMS 1.0 allows remote attackers to modify arbitrary pages via a direct request using the cid parameter.
- CVE-2009-48801 PoCMultiple integer overflows in the strfmon implementation in the GNU C Library (aka glibc or libc6) 2.10.1 and earlier allow…
- CVE-2009-48833 PoCsSQL injection vulnerability in index.php in PHPRecipeBook 2.24 and 2.39 allows remote attackers to execute arbitrary SQL commands via the…
- CVE-2009-48841 PoCMultiple SQL injection vulnerabilities in phpCommunity 2 2.1.8, when magic_quotes_gpc is disabled, allow remote attackers to execute…
- CVE-2009-48851 PoCCross-site scripting (XSS) vulnerability in templates/1/login.php in phpCommunity 2 2.1.8 allows remote attackers to inject arbitrary web…
- CVE-2009-48862 PoCsMultiple directory traversal vulnerabilities in phpCommunity 2 2.1.8 allow remote attackers to read arbitrary files via a .. (dot dot) in…
- CVE-2009-48871 PoCPHP remote file inclusion vulnerability in index.php in CMS S.Builder 3.7 and earlier, when register_globals is enabled, allows remote…
- CVE-2009-48881 PoCCross-site scripting (XSS) vulnerability in poster.php in PHortail 1.2.1 allows remote attackers to inject arbitrary web script or HTML…
- CVE-2009-48892 PoCsSQL injection vulnerability in books.php in the Book Panel (book_panel) module for PHP-Fusion allows remote attackers to execute arbitrary…
- CVE-2009-48911 PoCSQL injection vulnerability in index.php in CS-Cart 2.0.0 Beta 3 allows remote attackers to execute arbitrary SQL commands via the…
- CVE-2009-48922 PoCsSQL injection vulnerability in Content Management System WEBjump! allows remote attackers to execute arbitrary SQL commands via the id…
- CVE-2009-49052 PoCsMultiple cross-site request forgery (CSRF) vulnerabilities in index.php in Acc Statistics 1.1 allow remote attackers to hijack the…
- CVE-2009-49062 PoCsCross-site request forgery (CSRF) vulnerability in index.php in Acc PHP eMail 1.1 allows remote attackers to hijack the authentication of…
- CVE-2009-49071 PoCMultiple cross-site request forgery (CSRF) vulnerabilities in oBlog allow remote attackers to hijack the authentication of administrators…
- CVE-2009-49081 PoCMultiple cross-site scripting (XSS) vulnerabilities in oBlog allow remote attackers to inject arbitrary web script or HTML via the (1)…
- CVE-2009-49252 PoCsMultiple SQL injection vulnerabilities in Portale e-commerce Creasito (aka creasito e-commerce content manager) 1.3.16, when…
- CVE-2009-49265 PoCsMultiple cross-site scripting (XSS) vulnerabilities in Online Contact Manager (formerly EContact PRO) 3.0 allow remote attackers to inject…
- CVE-2009-49272 PoCsWB News 2.1.2 allows remote attackers to bypass authentication and gain administrative access via a modified WBNEWS cookie, as…
- CVE-2009-49281 PoCPHP remote file inclusion vulnerability in config.php in TotalCalendar 2.4 allows remote attackers to execute arbitrary PHP code via a URL…
- CVE-2009-49292 PoCsadmin/manage_users.php in TotalCalendar 2.4 does not require administrative authentication, which allows remote attackers to change…
- CVE-2009-49311 PoCStack-based buffer overflow in Groovy Media Player 1.1.0 allows remote attackers to cause a denial of service (application crash) or…
- CVE-2009-49322 PoCsStack-based buffer overflow in 1by1 1.67 (aka 1.6.7.0) allows remote attackers to cause a denial of service (application crash) or…
- CVE-2009-49332 PoCsMultiple SQL injection vulnerabilities in login.php in EZ Webitor allow remote attackers to execute arbitrary SQL commands via the (1)…
- CVE-2009-49341 PoCCross-site scripting (XSS) vulnerability in index.php in Online Photo Pro 2.0 allows remote attackers to inject arbitrary web script or…
- CVE-2009-49353 PoCsSQL injection vulnerability in ogp_show.php in Online Guestbook Pro allows remote attackers to execute arbitrary SQL commands via the…
- CVE-2009-49362 PoCsMultiple SQL injection vulnerabilities in Small Pirate (SPirate) 2.1 allow remote attackers to execute arbitrary SQL commands via (1) the…
- CVE-2009-49371 PoCCross-site scripting (XSS) vulnerability in Small Pirate (SPirate) 2.1 allows remote attackers to inject arbitrary web script or HTML via…
- CVE-2009-49381 PoCSQL injection vulnerability in the JVideo! (com_jvideo) component 0.3.11c Beta and 0.3.x for Joomla! allows remote attackers to execute…
- CVE-2009-49393 PoCsMultiple cross-site scripting (XSS) vulnerabilities in index.php in AdPeeps 8.5d1 allow remote attackers to inject arbitrary web script or…
- CVE-2009-49402 PoCsSQL injection vulnerability in index.php in Zeus Cart 2.3 and earlier allows remote attackers to execute arbitrary SQL commands via the…
- CVE-2009-49572 PoCsDirectory traversal vulnerability in loadpanel.php in Interspire ActiveKB allows remote attackers to read arbitrary files and possibly…
- CVE-2009-49582 PoCsSQL injection vulnerability in video.php in EMO Breeder Manager (aka EMO Breader Manager) allows remote attackers to execute arbitrary SQL…
- CVE-2009-49601 PoCDirectory traversal vulnerability in modules/backup/download.php in Lanai Core 0.6 allows remote attackers to read arbitrary files via a…
- CVE-2009-49612 PoCsLanai Core 0.6 allows remote attackers to obtain configuration information via a direct request to info.php, which calls the phpinfo…
- CVE-2009-49625 PoCsStack-based buffer overflow in Fat Player 0.6b allows remote attackers to execute arbitrary code via a long string in a .wav file. NOTE:…
- CVE-2009-49642 PoCsStack-based buffer overflow in KSP 2006 FINAL allows remote attackers to execute arbitrary code via a long string in a .M3U playlist file.
- CVE-2009-49732 PoCsSQL injection vulnerability in rss.php in TotalCalendar 2.4 allows remote attackers to execute arbitrary SQL commands via the selectedCal…
- CVE-2009-49742 PoCsDirectory traversal vulnerability in box_display.php in TotalCalendar 2.4 allows remote attackers to read arbitrary files and possibly…
- CVE-2009-49772 PoCsPHP remote file inclusion vulnerability in index.php in MyBackup 1.4.0 allows remote authenticated users to execute arbitrary PHP code via…
- CVE-2009-49782 PoCsDirectory traversal vulnerability in down.php in MyBackup 1.4.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the…
- CVE-2009-49822 PoCsSQL injection vulnerability in the select function in Irokez CMS 0.7.1, when magic_quotes_gpc is disabled, allows remote attackers to…
- CVE-2009-49833 PoCsMultiple cross-site scripting (XSS) vulnerabilities in Silurus Classifieds 1.0 allow remote attackers to inject arbitrary web script or…
- CVE-2009-49842 PoCsMultiple cross-site scripting (XSS) vulnerabilities in Accessories Me PHP Affiliate Script 1.4 allow remote attackers to inject arbitrary…
- CVE-2009-49852 PoCsSQL injection vulnerability in browse.php in Accessories Me PHP Affiliate Script 1.4 allows remote attackers to execute arbitrary SQL…
- CVE-2009-49862 PoCsDirectory traversal vulnerability in index.php in In-Portal 4.3.1, when magic_quotes_gpc is disabled, allows remote attackers to read…
- CVE-2009-49872 PoCsadmin/header.php in Scripteen Free Image Hosting Script 2.3 allows remote attackers to bypass authentication and gain administrative…
- CVE-2009-49884 PoCsStack-based buffer overflow in NT_Naming_Service.exe in SAP Business One 2005 A 6.80.123 and 6.80.320 allows remote attackers to execute…
- CVE-2009-49891 PoCCross-site scripting (XSS) vulnerability in index.php in AJ Auction Pro OOPD 3.0 allows remote attackers to inject arbitrary web script or…
- CVE-2009-49911 PoCCross-site scripting (XSS) vulnerability in users/resume_register.php in Omnistar Recruiting allows remote attackers to inject arbitrary…
- CVE-2009-49922 PoCsSQL injection vulnerability in paidbanner.php in LM Starmail Paidmail 2.0 allows remote attackers to execute arbitrary SQL commands via…
- CVE-2009-49932 PoCsPHP remote file inclusion vulnerability in home.php in LM Starmail Paidmail 2.0 allows remote attackers to execute arbitrary PHP code via…