CVE-2009-5000 to CVE-2009-5999
33 CVEs with public proof-of-concept exploits.
- CVE-2009-50032 PoCsSQL injection vulnerability in click.php in e-soft24 Banner Exchange Script 1.0 allows remote attackers to execute arbitrary SQL commands…
- CVE-2009-50182 PoCsStack-based buffer overflow in gif2png.c in gif2png 2.5.3 and earlier might allow context-dependent attackers to execute arbitrary code…
- CVE-2009-50194 PoCsWeb Wiz NewsPad stores sensitive information under the web root with insufficient access control, which allows remote attackers to…
- CVE-2009-50201 PoCOpen redirect vulnerability in awredir.pl in AWStats before 6.95 allows remote attackers to redirect users to arbitrary web sites and…
- CVE-2009-50221 PoCHeap-based buffer overflow in tif_ojpeg.c in the OJPEG decoder in LibTIFF before 3.9.5 allows remote attackers to execute arbitrary code…
- CVE-2009-50261 PoCThe executable comment feature in MySQL 5.0.x before 5.0.93 and 5.1.x before 5.1.50, when running in certain slave configurations in which…
- CVE-2009-50292 PoCsInteger overflow in the __tzfile_read function in glibc before 2.15 allows context-dependent attackers to cause a denial of service…
- CVE-2009-50481 PoCCookie Dump Servlet stored XSS vulnerability in jetty though 6.1.20.
- CVE-2009-50491 PoCWebApp JSP Snoop page XSS in jetty though 6.1.21.
- CVE-2009-50651 PoCCross-site scripting (XSS) vulnerability in feedparser.py in Universal Feed Parser (aka feedparser or python-feedparser) before 5.0 allows…
- CVE-2009-50671 PoCDirectory traversal vulnerability in html2ps before 1.0b6 allows remote attackers to read arbitrary files via a .. (dot dot) in the…
- CVE-2009-50681 PoCThere is a file disclosure vulnerability in SMF (Simple Machines Forum) affecting versions through v2.0.3. On some configurations a SMF…
- CVE-2009-50872 PoCsDirectory traversal vulnerability in geohttpserver in Geovision Digital Video Surveillance System 8.2 allows remote attackers to read…
- CVE-2009-50882 PoCsSQL injection vulnerability in secure/index.php in IdeaCart 0.02 allows remote attackers to execute arbitrary SQL commands via the cID…
- CVE-2009-50892 PoCsDirectory traversal vulnerability in index.php in IdeaCart 0.02 and 0.02a allows remote attackers to read arbitrary files via a .. (dot…
- CVE-2009-50902 PoCsSQL injection vulnerability in editcomments.php in Bloggeruniverse Beta 2, when magic_quotes_gpc is disabled, allows remote attackers to…
- CVE-2009-50912 PoCsSQL injection vulnerability in page.php in Vlinks 1.0.3 and 1.1.6 allows remote attackers to execute arbitrary SQL commands via the id…
- CVE-2009-50932 PoCsDirectory traversal vulnerability in gastbuch.php in Gästebuch (Gastebuch) 1.6 allows remote attackers to read arbitrary files via a ..…
- CVE-2009-50942 PoCsSQL injection vulnerability in info.php in CMS Faethon 2.2.0 Ultimate allows remote attackers to execute arbitrary SQL commands via the…
- CVE-2009-50952 PoCsPHP remote file inclusion vulnerability in index_inc.php in ea gBook 0.1 and 0.1.4 allows remote attackers to execute arbitrary PHP code…
- CVE-2009-50981 PoCThe LunaSysMgr process in Palm Pre WebOS 1.1 and earlier, when not viewing web pages in landscape mode, allows remote attackers to cause a…
- CVE-2009-51022 PoCsSQL injection vulnerability in default.asp in ATCOM Netvolution 1.0 ASP allows remote attackers to execute arbitrary SQL commands via the…
- CVE-2009-51032 PoCsCross-site scripting (XSS) vulnerability in ATCOM Netvolution 1.0 ASP allows remote attackers to inject arbitrary web script or HTML via…
- CVE-2009-51099 PoCsStack-based buffer overflow in Mini-Stream Ripper 3.0.1.1 allows remote attackers to execute arbitrary code via a long entry in a .pls file.
- CVE-2009-51121 PoCwgarcmin.cgi in WebGlimpse 2.18.7 and earlier allows remote attackers to obtain the installation path via a crafted request.
- CVE-2009-51142 PoCsDirectory traversal vulnerability in wgarcmin.cgi in WebGlimpse 2.18.7 and earlier allows remote attackers to read arbitrary files via a…
- CVE-2009-51342 PoCsBuffer overflow in the "create torrent dialog" functionality in uTorrent 1.8.3 build 15772, and possibly other versions before 1.8.3…
- CVE-2009-51352 PoCsThe Java XML parser in Echo before 2.1.1 and 3.x before 3.0.b6 allows remote attackers to read arbitrary files via a request containing an…
- CVE-2009-51372 PoCsStack-based buffer overflow in Mini-stream CastRipper 2.50.70 allows remote attackers to execute arbitrary code via a long URL in the…
- CVE-2009-51412 PoCsFormat string vulnerability in War FTP Daemon (warftpd) 1.82 RC 12 allows remote authenticated users to cause a denial of service (crash)…
- CVE-2009-51471 PoCDL::dlopen in Ruby 1.8, 1.9.0, 1.9.2, 1.9.3, 2.0.0 before patchlevel 648, and 2.1 before 2.1.8 opens libraries with tainted names.
- CVE-2009-51541 PoCAn issue was discovered on MOBOTIX S14 MX-V4.2.1.61 devices. There is a default password of meinsm for the admin account.
- CVE-2009-51592 PoCsInvision Power Board (aka IPB or IP.Board) 2.x through 3.0.4, when Internet Explorer 5 is used, allows XSS via a .txt attachment.