CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2009-3424

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in MaxCMS 3.11.20b, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) is_projectPath parameter to includes/InstantSite/inc.is_root.php; GLOBALS[thCMS_root] parameter to (2) classes/class.Tree.php, (3) includes/inc.thcms_admin_mediamanager.php, and (4) modul/mod.rssreader.php; is_path parameter to (5) class.tasklist.php, (6) class.thcms.php, (7) class.thcms_content.php, (8) class.thcms_modul_parent.php, (9) class.thcms_page.php, and (10) class.thcsm_user.php in classes/; and (11) includes/InstantSite/class.Tree.php; and thCMS_root parameter to (12) classes/class.thcms_modul.php; (13) inc.page_edit_tasklist.php, (14) inc.thcms_admin_overview_backup.php, and (15) inc.thcms_edit_content.php in includes/; and (16) class.thcms_modul_parent_xml.php, (17) mod.cmstranslator.php, (18) mod.download.php, (19) mod.faq.php, (20) mod.guestbook.php, (21) mod.html.php, (22) mod.menu.php, (23) mod.news.php, (24) mod.newsticker.php, (25) mod.rss.php, (26) mod.search.php, (27) mod.sendtofriend.php, (28) mod.sitemap.php, (29) mod.tagdoc.php, (30) mod.template.php, (31) mod.test.php, (32) mod.text.php, (33) mod.upload.php, and (34) mod.users.php in modul/.

    Published: 25 Sept 2009
    5
    Medium

    CVE-2009-3425

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in includes/inc.thcms_admin_dirtree.php in MaxCMS 3.11.20b allows remote attackers to read arbitrary files via directory traversal sequences in the thCMS_root parameter.

    Published: 25 Sept 2009
    7.2
    High

    CVE-2009-2682

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Role-Based Access Control (RBAC) in HP HP-UX B.11.23 and B.11.31 allows local users to bypass intended access restrictions via unknown vectors.

    Published: 24 Sept 2009
    9.3
    Critical

    CVE-2009-2817

    Last Modified: 23 Apr 2026

    Buffer overflow in Apple iTunes before 9.0.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted .pls file.

    Published: 24 Sept 2009
    7.2
    High

    CVE-2009-3390

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in the (1) iscsiadm and (2) iscsitadm programs in Sun Solaris 10, and OpenSolaris snv_28 through snv_109, allow local users with certain RBAC execution profiles to gain privileges via unknown vectors related to the libima library.

    Published: 24 Sept 2009
    9.3
    Critical

    CVE-2009-3338

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in EffectMatrix (E.M.) Magic Morph 1.95b allows remote attackers to execute arbitrary code via a long string in a .mor file.

    Published: 24 Sept 2009
    5
    Medium

    CVE-2009-3340

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in FreeSSHD 1.2.4 allows remote attackers to cause a denial of service via unknown vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.11. NOTE: as of 20090917, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.

    Published: 24 Sept 2009
    10
    Critical

    CVE-2009-3345

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in SAP Crystal Reports Server 2008 has unknown impact and attack vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.3 through 8.11. NOTE: as of 20090917, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.

    Published: 24 Sept 2009
    10
    Critical

    CVE-2009-3347

    Last Modified: 23 Apr 2026

    Buffer overflow on the D-Link DIR-400 wireless router allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.10 through 8.11. NOTE: as of 20090917, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.

    Published: 24 Sept 2009
    4.3
    Medium

    CVE-2009-3348

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Datavore Gyro 5.0 allows remote attackers to inject arbitrary web script or HTML via the cid parameter in a cat action to the home component.

    Published: 24 Sept 2009
    7.5
    High

    CVE-2009-3349

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Datavore Gyro 5.0 allows remote attackers to execute arbitrary SQL commands via the cid parameter in a cat action to the home component.

    Published: 24 Sept 2009
    10
    Critical

    CVE-2009-3352

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in the quota_by_role (Quota by role) module for Drupal have unknown impact and attack vectors.

    Published: 24 Sept 2009
    10
    Critical

    CVE-2009-3353

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in the Node2Node module for Drupal have unknown impact and attack vectors.

    Published: 24 Sept 2009
    4.3
    Medium

    CVE-2009-3355

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in profile.php in Datetopia Buy Dating Site 1.0 allows remote attackers to inject arbitrary web script or HTML via the s_r parameter.

    Published: 24 Sept 2009
    7.5
    High

    CVE-2009-3356

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Image voting 1.0 allows remote attackers to execute arbitrary SQL commands via the show parameter.

    Published: 24 Sept 2009
    7.5
    High

    CVE-2009-3358

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in profile.php in Tourism Scripts Adult Portal escort listing allows remote attackers to execute arbitrary SQL commands via the user_id parameter.

    Published: 24 Sept 2009
    7.5
    High

    CVE-2009-3361

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in PHP-IPNMonitor allows remote attackers to execute arbitrary SQL commands via the maincat_id parameter.

    Published: 24 Sept 2009
    7.5
    High

    CVE-2009-3362

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in printnews.php3 in SZNews 2.7 allows remote attackers to execute arbitrary PHP code via a URL in the id parameter.

    Published: 24 Sept 2009
    4.3
    Medium

    CVE-2009-3363

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the BUEditor module 5.x before 5.x-1.2 and 6.x before 6.x-1.4, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via input to the "plain textarea editor."

    Published: 24 Sept 2009
    9.3
    Critical

    CVE-2009-3364

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in FTPShell Client 4.1 RC2 allows remote FTP servers to execute arbitrary code via a long response to a PASV command.

    Published: 24 Sept 2009
    7.5
    High

    CVE-2009-3365

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in add-ons/modules/sysmanager/plugins/install.plugin.php in Aurora CMS 1.0.2 allows remote attackers to execute arbitrary PHP code via a URL in the AURORA_MODULES_FOLDER parameter.

    Published: 24 Sept 2009
    5
    Medium

    CVE-2009-3366

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in navigation.php in An image gallery 1.0 allows remote attackers to list arbitrary directories via a .. (dot dot) in the path parameter.

    Published: 24 Sept 2009
    4.3
    Medium

    CVE-2009-3367

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in An image gallery 1.0 allow remote attackers to inject arbitrary web script or HTML via the path parameter to (1) index.php and (2) main.php, and the (3) show parameter to main.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 24 Sept 2009
    7.5
    High

    CVE-2009-3335

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the TurtuShout component 0.11 for Joomla! allows remote attackers to execute arbitrary SQL commands via the Name field.

    Published: 24 Sept 2009
    7.5
    High

    CVE-2009-3336

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in auction_details.php in PHP Pro Bid allows remote attackers to execute arbitrary SQL commands via the auction_id parameter.

    Published: 24 Sept 2009
    7.5
    High

    CVE-2009-3357

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in the Hotel Booking Reservation System (aka HBS or com_hbssearch) component for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) h_id, (2) id, and (3) rid parameters to longDesc.php, and the h_id parameter to (4) detail.php, (5) detail1.php, (6) detail2.php, (7) detail3.php, (8) detail4.php, (9) detail5.php, (10) detail6.php, (11) detail7.php, and (12) detail8.php, different vectors than CVE-2008-5865, CVE-2008-5874, and CVE-2008-5875.

    Published: 24 Sept 2009
    7.5
    High

    CVE-2009-3342

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in frontend/assets/ajax/checkusername.php in the AlphaUserPoints (com_alphauserpoints) component 1.5.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the username2points parameter.

    Published: 24 Sept 2009
    10
    Critical

    CVE-2009-3350

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in the Subdomain Manager module for Drupal have unknown impact and attack vectors.

    Published: 24 Sept 2009
    4.3
    Medium

    CVE-2009-3359

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Match Agency BiZ 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) important parameter to edit_profile.php and (2) pid parameter to report.php.

    Published: 24 Sept 2009
    4.3
    Medium

    CVE-2009-3368

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Hotel Booking Reservation System (aka HBS or com_hbssearch) component for Joomla! allows remote attackers to inject arbitrary web script or HTML via the adult parameter in a showhoteldetails action to index.php.

    Published: 24 Sept 2009
    8.5
    High

    CVE-2009-2680

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Remote Management Interface (RMI) for MSL Tape Libraries and 1/8 G2 Tape Autoloaders in HP StorageWorks 1/8 G2 Tape Autoloader firmware 2.30 and earlier, MSL2024 Tape Library firmware 4.20 and earlier, MSL4048 Tape Library firmware 6.50 and earlier, and MSL8096 Tape Library firmware 8.90 and earlier allows remote attackers to cause a denial of service via unknown vectors.

    Published: 24 Sept 2009
    7.5
    High

    CVE-2009-3337

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Freetag (serendipity_event_freetag) plugin before 3.09 for Serendipity (S9Y) allows remote attackers to execute arbitrary SQL commands via an unspecified parameter associated with Meta keywords in a blog entry.

    Published: 24 Sept 2009
    7.8
    High

    CVE-2009-3339

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in McAfee Email and Web Security Appliance 5.1 VMtrial allows remote attackers to read arbitrary files via unknown vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.9 through 8.11. NOTE: as of 20090917, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.

    Published: 24 Sept 2009
    10
    Critical

    CVE-2009-3341

    Last Modified: 23 Apr 2026

    Buffer overflow on the Linksys WRT54GL wireless router allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.10 through 8.11. NOTE: as of 20090917, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.

    Published: 24 Sept 2009
    7.5
    High

    CVE-2009-3343

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in details.asp in HotWeb Rentals allows remote attackers to execute arbitrary SQL commands via the PropId parameter.

    Published: 24 Sept 2009
    5
    Medium

    CVE-2009-3344

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in SAP Crystal Reports Server 2008 on Windows XP allows attackers to cause a denial of service (infinite loop) via unknown vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.3 through 8.11. NOTE: as of 20090917, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.

    Published: 24 Sept 2009
    10
    Critical

    CVE-2009-3346

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in SAP Crystal Reports Server 2008 allows remote attackers to execute arbitrary code via unknown vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.3 through 8.11. NOTE: as of 20090917, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.

    Published: 24 Sept 2009
    10
    Critical

    CVE-2009-3351

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in the Node Browser module for Drupal have unknown impact and attack vectors.

    Published: 24 Sept 2009
    10
    Critical

    CVE-2009-3354

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in the Rest API module for Drupal have unknown impact and attack vectors.

    Published: 24 Sept 2009
    4.3
    Medium

    CVE-2009-3360

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Datemill 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) return parameter to photo_view.php, and st parameter to (2) photo_search.php and (3) search.php.

    Published: 24 Sept 2009
    4.6
    Medium

    CVE-2009-2905

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in textbox.c in newt 0.51.5, 0.51.6, and 0.52.2 allows local users to cause a denial of service (application crash) or possibly execute arbitrary code via a request to display a crafted text dialog box.

    Published: 24 Sept 2009
    7.5
    High

    CVE-2009-3306

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in include/header.php in ClearSite 4.50 allows remote attackers to execute arbitrary PHP code via a URL in the cs_base_path parameter.

    Published: 23 Sept 2009
    7.5
    High

    CVE-2009-3308

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in show-cat.php in FanUpdate 2.2.1 allows remote attackers to execute arbitrary SQL commands via the listingid parameter.

    Published: 23 Sept 2009
    6.5
    Medium

    CVE-2009-3313

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in FMyClone 2.3 allow remote attackers to execute arbitrary SQL commands via the comp parameter to (1) index.php and (2) editComments.php, and (3) allow remote authenticated administrators to execute arbitrary SQL commands via the id parameter in a comment action to edit.php.

    Published: 23 Sept 2009
    7.5
    High

    CVE-2009-3314

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in ladders.php in Elite Gaming Ladders 3.2 allows remote attackers to execute arbitrary SQL commands via the platform parameter.

    Published: 23 Sept 2009
    7.5
    High

    CVE-2009-3315

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin/index.php in NeLogic Nephp Publisher Enterprise 3.5.9 and 4.5 allows remote attackers to execute arbitrary SQL commands via the Username field.

    Published: 23 Sept 2009
    7.5
    High

    CVE-2009-3317

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in pages/pageHeader.php in OpenSiteAdmin 0.9.7 BETA allows remote attackers to execute arbitrary PHP code via a URL in the path parameter, a different vector than CVE-2008-0648.

    Published: 23 Sept 2009
    6.8
    Medium

    CVE-2009-3321

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in SaphpLesson 4.3, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the CLIENT_IP HTTP header.

    Published: 23 Sept 2009
    7.8
    High

    CVE-2009-3322

    Last Modified: 23 Apr 2026

    The Siemens Gigaset SE361 WLAN router allows remote attackers to cause a denial of service (device reboot) via a flood of crafted TCP packets to port 1723.

    Published: 23 Sept 2009
    7.5
    High

    CVE-2009-3324

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in include/prodler.class.php in ProdLer 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the sPath parameter.

    Published: 23 Sept 2009