CVE Feed

    Dashboard / CVE

    9.3
    Critical

    CVE-2009-2121

    Last Modified: 23 Apr 2026

    Buffer overflow in the browser kernel in Google Chrome before 2.0.172.33 allows remote HTTP servers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted response.

    Published: 23 Jun 2009
    4.3
    Medium

    CVE-2009-2178

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in website.php in phpDatingClub 3.7 allows remote attackers to inject arbitrary web script or HTML via the page parameter.

    Published: 23 Jun 2009
    7.5
    High

    CVE-2009-2179

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in search.php in phpDatingClub 3.7 allows remote attackers to execute arbitrary SQL commands via the sform[day] parameter.

    Published: 23 Jun 2009
    7.5
    High

    CVE-2009-2183

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in admin-files/ad.php in Campsite 3.3.0 RC1 allows remote attackers to read and possibly execute arbitrary local files via a .. (dot dot) in the GLOBALS[g_campsiteDir] parameter.

    Published: 23 Jun 2009
    5
    Medium

    CVE-2009-2184

    Last Modified: 23 Apr 2026

    Absolute path traversal vulnerability in forcedownload.php in Gravy Media Photo Host 1.0.8 allows remote attackers to read arbitrary files via an encoded "/" (slash) in the file parameter.

    Published: 23 Jun 2009
    7.5
    High

    CVE-2009-2176

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in fuzzylime (cms) 3.03a and earlier, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the (1) list parameter to code/confirm.php and the (2) template parameter to code/display.php.

    Published: 23 Jun 2009
    9.3
    Critical

    CVE-2009-0691

    Last Modified: 23 Apr 2026

    The Foxit JPEG2000/JBIG2 Decoder add-on before 2.0.2009.616 for Foxit Reader 3.0 before Build 1817 does not properly handle a fatal error during decoding of a JPEG2000 (aka JPX) header, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted PDF file that triggers an invalid memory access.

    Published: 23 Jun 2009
    6.8
    Medium

    CVE-2009-2182

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Campsite 3.3.0 RC1 allow remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[g_campsiteDir] parameter to (1) ad_popup.php, (2) camp_html.php, (3) init_content.php, (4) logout.php, (5) menu.php, and (6) set-author.php in admin-files/; (7) conf/liveuser_configuration.php; (8) include/phorum_load.php; (9) CommandProcessor.php and (10) index.php in admin-files/article_import; and (11) add.php, (12) add_move.php, (13) autopublish.php, and (14) autopublish_del.php in admin-files/articles/.

    Published: 23 Jun 2009
    4.3
    Medium

    CVE-2009-2172

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in forum/radioandtv.php in the Radio and TV Player addon for vBulletin allows remote registered users to inject arbitrary web script or HTML via the station parameter.

    Published: 23 Jun 2009
    3.5
    Low

    CVE-2009-2173

    Last Modified: 23 Apr 2026

    The LAN game feature in Carom3D 5.06 allows remote authenticated users to cause a denial of service (application hang) via a crafted HTTP request to TCP port 28012.

    Published: 23 Jun 2009
    5
    Medium

    CVE-2009-2174

    Last Modified: 23 Apr 2026

    GUPnP 0.12.7 allows remote attackers to cause a denial of service (crash) via an empty (1) subscription or (2) control message.

    Published: 23 Jun 2009
    4.3
    Medium

    CVE-2009-2175

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the flattenIncrementally function in flatten.c in xcftools 1.0.4, as reachable from the (1) xcf2pnm and (2) xcf2png utilities, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted image that causes a conversion to a location "above or to the left of the canvas." NOTE: some of these details are obtained from third party information.

    Published: 23 Jun 2009
    6.8
    Medium

    CVE-2009-2177

    Last Modified: 23 Apr 2026

    code/display.php in fuzzylime (cms) 3.03a and earlier, when magic_quotes_gpc is disabled, allows remote attackers to conduct directory traversal attacks and overwrite arbitrary files via a "....//" (dot dot) in the s parameter, which is collapsed into a "../" value.

    Published: 23 Jun 2009
    5
    Medium

    CVE-2009-2180

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in upfiles/index.php in Pc4 Uploader 10.0 and earlier allow remote attackers to read arbitrary files via (1) a .. (dot dot) or (2) absolute path in the file parameter.

    Published: 23 Jun 2009
    4.3
    Medium

    CVE-2009-2181

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in admin-files/templates/list_dir.php in Campsite 3.3.0 RC1 allows remote attackers to inject arbitrary web script or HTML via the listbasedir parameter.

    Published: 23 Jun 2009
    4.3
    Medium

    CVE-2009-2170

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Mahara 1.0 before 1.0.12 and 1.1 before 1.1.5 allow remote attackers to inject arbitrary web script or HTML via unknown vectors.

    Published: 23 Jun 2009
    4
    Medium

    CVE-2009-2171

    Last Modified: 23 Apr 2026

    Mahara 1.1 before 1.1.5 does not apply permission checks when saving a view that contains artefacts, which allows remote authenticated users to read another user's artefact.

    Published: 23 Jun 2009
    9.3
    Critical

    CVE-2009-1886

    Last Modified: 23 Apr 2026

    Multiple format string vulnerabilities in client/client.c in smbclient in Samba 3.2.0 through 3.2.12 might allow context-dependent attackers to execute arbitrary code via format string specifiers in a filename.

    Published: 23 Jun 2009
    10
    Critical

    CVE-2009-3637

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the M_AddToServerList function in client/menu.c in Red Planet Arena Alien Arena 7.30 allows remote attackers to execute arbitrary code via a packet with a crafted server description to UDP port 27901 followed by a packet with a long print command.

    Published: 23 Jun 2009
    5.8
    Medium

    CVE-2009-1888

    Last Modified: 23 Apr 2026

    The acl_group_override function in smbd/posix_acls.c in smbd in Samba 3.0.x before 3.0.35, 3.1.x and 3.2.x before 3.2.13, and 3.3.x before 3.3.6, when dos filemode is enabled, allows remote attackers to modify access control lists for files via vectors related to read access to uninitialized memory.

    Published: 23 Jun 2009
    9.3
    Critical

    CVE-2009-2169

    Last Modified: 23 Apr 2026

    Insecure method vulnerability in the PDFVIEWER.PDFViewerCtrl.1 ActiveX control (pdfviewer.ocx) in Edraw PDF Viewer Component before 3.2.0.126 allows remote attackers to create and overwrite arbitrary files via a URL argument to the FtpConnect argument and a target filename argument to the FtpDownloadFile method. NOTE: this can be leveraged for code execution by writing to a Startup folder.

    Published: 22 Jun 2009
    10
    Critical

    CVE-2008-6833

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in commsrss.php in fuzzylime (cms) before 3.01b allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in a files array element for a blogs action, as demonstrated by the files[0] parameter.

    Published: 22 Jun 2009
    10
    Critical

    CVE-2008-6834

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in fuzzylime (cms) 3.01 and 3.01a allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the s parameter to code/commupdate.php in a count action or (2) the heads parameter to code/newsheads.php. NOTE: the blog.php vector is already covered by CVE-2008-3164.

    Published: 22 Jun 2009
    4.3
    Medium

    CVE-2009-2163

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in login/default.aspx in Sitecore CMS before 6.0.2 Update-1 090507 allows remote attackers to inject arbitrary web script or HTML via the sc_error parameter.

    Published: 22 Jun 2009
    6.8
    Medium

    CVE-2009-2167

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in cpanel/login.php in EgyPlus 7ammel (aka 7ml) 1.0.1 and earlier, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter.

    Published: 22 Jun 2009
    7.5
    High

    CVE-2009-2165

    Last Modified: 23 Apr 2026

    SerendipityNZ (aka SimpleBoxes) Serene Bach 2.20R and earlier, and 3.00 beta023 and earlier 3.x versions, uses a predictable session id, which makes it easier for remote attackers to hijack sessions via a modified id.

    Published: 22 Jun 2009
    6.8
    Medium

    CVE-2009-2164

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Kjtechforce mailman beta1, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via (1) the code parameter to activate.php or (2) the dest parameter to index.php.

    Published: 22 Jun 2009
    5
    Medium

    CVE-2009-2166

    Last Modified: 23 Apr 2026

    Absolute path traversal vulnerability in cvs.php in OCS Inventory NG before 1.02.1 on Unix allows remote attackers to read arbitrary files via a full pathname in the log parameter.

    Published: 22 Jun 2009
    9.8
    Critical

    CVE-2009-2168

    Last Modified: 23 Apr 2026

    cpanel/login.php in EgyPlus 7ammel (aka 7ml) 1.0.1 and earlier sends a redirect to the web browser but does not exit when the supplied credentials are incorrect, which allows remote attackers to bypass authentication by providing arbitrary username and password parameters.

    Published: 22 Jun 2009
    6.4
    Medium

    CVE-2009-2159

    Last Modified: 23 Apr 2026

    backup-database.php in TorrentTrader Classic 1.09 does not require administrative authentication, which allows remote attackers to create and download a backup database by making a direct request and then retrieving a .gz file from backups/.

    Published: 22 Jun 2009
    5
    Medium

    CVE-2009-2160

    Last Modified: 23 Apr 2026

    TorrentTrader Classic 1.09 allows remote attackers to (1) obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function; and allows remote attackers to (2) obtain other potentially sensitive information via a direct request to check.php.

    Published: 22 Jun 2009
    5.1
    Medium

    CVE-2009-2161

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in backend/admin-functions.php in TorrentTrader Classic 1.09, when used on a case-insensitive web site, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the ss_uri parameter, in conjunction with a modified component name.

    Published: 22 Jun 2009
    4.3
    Medium

    CVE-2009-2162

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the XOOPS MANIAC PukiWikiMod module 1.6.6.2 and earlier for XOOPS allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 22 Jun 2009
    4.3
    Medium

    CVE-2009-2155

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in report/ReportViewAction.do in WebNMS Free Edition 5 allows remote attackers to inject arbitrary web script or HTML via the type parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 22 Jun 2009
    3.5
    Low

    CVE-2009-2156

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in TorrentTrader Classic 1.09 allow remote authenticated users to inject arbitrary web script or HTML via (1) the Title field to requests.php, related to viewrequests.php; and (2) the Torrent Name field to torrents-upload.php, related to the logging of torrent uploads; and allow remote attackers to inject arbitrary web script or HTML via (3) the ttversion parameter to themes/default/footer.php, the (4) SITENAME and (5) CURUSER[username] parameters to themes/default/header.php, (6) the todayactive parameter to visitorstoday.php, (7) the activepeople parameter to visitorsnow.php, (8) the faq_categ[999][title] parameter to faq.php, and (9) the keepget parameter to torrents-details.php.

    Published: 22 Jun 2009
    6.5
    Medium

    CVE-2009-2157

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in TorrentTrader Classic 1.09 allow remote authenticated users to execute arbitrary SQL commands via (1) the origmsg parameter to account-inbox.php; the categ parameter to (2) delreq.php and (3) admin-delreq.php; (4) the choice parameter to index.php; (5) the id parameter to modrules.php in an edited (aka edit) action; the (6) user, (7) torrent, (8) forumid, and (9) forumpost parameters to report.php; (10) the delmp parameter to take-deletepm.php; (11) the delreport parameter to takedelreport.php; (12) the delreq parameter to takedelreq.php; (13) the clases parameter to takestaffmess.php; and (14) the warndisable parameter to takewarndisable.php; and allow remote attackers to execute arbitrary SQL commands via (15) the wherecatin parameter to browse.php, (16) the limit parameter to today.php, and (17) the where parameter to torrents-details.php.

    Published: 22 Jun 2009
    7.5
    High

    CVE-2009-2158

    Last Modified: 23 Apr 2026

    account-recover.php in TorrentTrader Classic 1.09 chooses random passwords from an insufficiently large set, which makes it easier for remote attackers to obtain a password via a brute-force attack.

    Published: 22 Jun 2009
    7.5
    High

    CVE-2009-2142

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in admin/index.asp in Zip Store Chat 4.0 and 5.0 allow remote attackers to execute arbitrary SQL commands via the (1) login and (2) senha parameters.

    Published: 22 Jun 2009
    7.5
    High

    CVE-2009-2143

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in firestats-wordpress.php in the FireStats plugin before 1.6.2-stable for WordPress allows remote attackers to execute arbitrary PHP code via a URL in the fs_javascript parameter.

    Published: 22 Jun 2009
    7.5
    High

    CVE-2009-2144

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the FireStats plugin before 1.6.2-stable for WordPress allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 22 Jun 2009
    6
    Medium

    CVE-2009-2146

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in the Compose Email feature in the Emails module in Sugar Community Edition (aka SugarCRM) before 5.2f allows remote authenticated users to execute arbitrary code by uploading a file with only an extension in its name, then accessing the file via a direct request to a modified filename under cache/modules/Emails/, as demonstrated using .php as the entire original name.

    Published: 22 Jun 2009
    5
    Medium

    CVE-2009-2151

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in AdaptWeb 0.9.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the newlang parameter.

    Published: 22 Jun 2009
    7.5
    High

    CVE-2009-2148

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in news/index.php in Campus Virtual-LMS allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 22 Jun 2009
    4.3
    Medium

    CVE-2009-2153

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Impleo Music Collection 2.0 allows remote attackers to inject arbitrary web script or HTML via the sort parameter.

    Published: 22 Jun 2009
    4.3
    Medium

    CVE-2009-2141

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in TBDev.NET 01-01-08 allow remote attackers to inject arbitrary web script or HTML via (1) the returnto parameter to makepoll.php, (2) the returnto parameter in a delete action to polls.php, or the (3) Info or (4) Avatar field to my.php.

    Published: 22 Jun 2009
    4.3
    Medium

    CVE-2009-2145

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in transLucid 1.75 allow remote attackers to inject arbitrary web script or HTML via the (a) NodeID and (b) action parameters to the default URI, and the (c) NodeID parameter to the default URI for the admin section; and allow remote authenticated users to inject arbitrary web script or HTML via the (d) Title (aka page name) and (e) Url fields in a (1) new or (2) modified page.

    Published: 22 Jun 2009
    7.5
    High

    CVE-2009-2147

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in fdown.php in phpWebThings 1.5.2 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 22 Jun 2009
    4.3
    Medium

    CVE-2009-2149

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Campus Virtual-LMS allow remote attackers to inject arbitrary web script or HTML via the (1) courseid parameter to enrolments/step1.php, or the (2) search or (3) siteid parameter to files/shared_list.php.

    Published: 22 Jun 2009
    6.8
    Medium

    CVE-2009-2150

    Last Modified: 23 Apr 2026

    Multiple cross-site request forgery (CSRF) vulnerabilities in Campus Virtual-LMS allow (1) remote attackers to hijack the authentication of arbitrary users for requests that terminate a session via login/logout.php, and might allow remote attackers to hijack the authentication of certain users via a (2) ADD or (3) DELETE action to enrolments/step2.php.

    Published: 22 Jun 2009
    7.5
    High

    CVE-2009-2152

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in a_index.php in AdaptWeb 0.9.2 allows remote attackers to execute arbitrary SQL commands via the CodigoDisciplina parameter in a TopicosCadastro1 action.

    Published: 22 Jun 2009