CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2009-0742

    Last Modified: 23 Apr 2026

    The username command in Cisco ACE Application Control Engine Module for Catalyst 6500 Switches and 7600 Routers and Cisco ACE 4710 Application Control Engine Appliance stores a cleartext password by default, which allows context-dependent attackers to obtain sensitive information.

    Published: 26 Feb 2009
    7.5
    High

    CVE-2008-6294

    Last Modified: 23 Apr 2026

    admin/Index.php in Acc Statistics 1.1 allows remote attackers to bypass authentication and gain administrative access by setting the username_cookie cookie to "admin."

    Published: 26 Feb 2009
    4.3
    Medium

    CVE-2008-6295

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Camera Life 2.6.2b8 allow remote attackers to inject arbitrary web script or HTML via the q parameter to (1) search.php and (2) rss.php; the query string after the image name in (3) photos/photo; the path parameter to (4) folder.php; page parameter and REQUEST_URI to (5) login.php; ver parameter to (6) media.php; theme parameter to (7) modules/iconset/iconset-debug.php; and the REQUEST_URI to (8) index.php.

    Published: 26 Feb 2009
    7.5
    High

    CVE-2008-6296

    Last Modified: 23 Apr 2026

    admin.php in Maran PHP Shop allows remote attackers to bypass authentication and gain administrative access by setting the user cookie to "demo."

    Published: 26 Feb 2009
    5
    Medium

    CVE-2008-6298

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in sISAPILocation before 1.0.2.2 allows remote attackers to bypass intended access restrictions for character encoding and the cookie secure flag via unknown vectors related to the "HTTP header rewrite function."

    Published: 26 Feb 2009
    7.5
    High

    CVE-2008-6301

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in shoutbox_view.php in the Small ShoutBox module 1.4 for phpBB allows remote attackers to execute arbitrary SQL commands via the id parameter in a delete action.

    Published: 26 Feb 2009
    9.3
    Critical

    CVE-2009-0187

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Orbit Downloader 2.8.2 and 2.8.3, and possibly other versions before 2.8.5, allows remote attackers to execute arbitrary code via a crafted HTTP URL with a long host name, which is not properly handled when constructing a "Connecting" log message.

    Published: 26 Feb 2009
    4.3
    Medium

    CVE-2009-0522

    Last Modified: 23 Apr 2026

    Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 on Windows allows remote attackers to trick a user into visiting an arbitrary URL via an unspecified manipulation of the "mouse pointer display," related to a "Clickjacking attack."

    Published: 26 Feb 2009
    4.3
    Medium

    CVE-2009-0523

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Adobe RoboHelp Server 6 and 7 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, which is not properly handled when displaying the Help Errors log.

    Published: 26 Feb 2009
    9
    Critical

    CVE-2009-0615

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in Cisco Application Networking Manager (ANM) before 2.0 and Application Control Engine (ACE) Device Manager before A3(2.1) allows remote authenticated users to read or modify arbitrary files via unspecified vectors, related to "invalid directory permissions."

    Published: 26 Feb 2009
    10
    Critical

    CVE-2009-0616

    Last Modified: 23 Apr 2026

    Cisco Application Networking Manager (ANM) before 2.0 uses default usernames and passwords, which makes it easier for remote attackers to access the application, or cause a denial of service via configuration changes, related to "default user credentials during installation."

    Published: 26 Feb 2009
    10
    Critical

    CVE-2009-0620

    Last Modified: 23 Apr 2026

    Cisco ACE Application Control Engine Module for Catalyst 6500 Switches and 7600 Routers before A2(1.1) uses default (1) usernames and (2) passwords for (a) the administrator and (b) web management, which makes it easier for remote attackers to perform configuration changes or obtain operating-system access.

    Published: 26 Feb 2009
    7.8
    High

    CVE-2009-0623

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Cisco ACE Application Control Engine Module for Catalyst 6500 Switches and 7600 Routers before A2(1.3) and Cisco ACE 4710 Application Control Engine Appliance before A3(2.1) allows remote attackers to cause a denial of service (device reload) via a crafted SSH packet.

    Published: 26 Feb 2009
    5.5
    Medium

    CVE-2009-2737

    Last Modified: 23 Apr 2026

    The EditCSVAction function in cgi/actions.py in Roundup 1.2 before 1.2.1, 1.4 through 1.4.6, and possibly other versions does not properly check permissions, which allows remote authenticated users with edit or create privileges for a class to modify arbitrary items within that class, as demonstrated by editing all queries, modifying settings, and adding roles to users.

    Published: 26 Feb 2009
    6.8
    Medium

    CVE-2008-6274

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in index.php in FamilyProject 2.0 allow remote attackers to execute arbitrary SQL commands via (1) the logmbr parameter (aka login field) or (2) the mdpmbr parameter (aka pass or "Mot de passe" field). NOTE: some of these details are obtained from third party information.

    Published: 25 Feb 2009
    4.3
    Medium

    CVE-2008-6275

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the User Karma module 5.x before 5.x-1.13 and 6.x before 6.x-1.0-beta1, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified messages.

    Published: 25 Feb 2009
    7.8
    High

    CVE-2008-6279

    Last Modified: 23 Apr 2026

    RakhiSoftware Price Comparison Script (aka Shopping Cart) allows remote attackers to obtain sensitive information via an invalid PHPSESSID cookie, which reveals the installation path in an error message.

    Published: 25 Feb 2009
    4.3
    Medium

    CVE-2008-6280

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in apply.cgi on the Linksys WRT160N allows remote attackers to inject arbitrary web script or HTML via the action parameter in a DHCP_Static operation.

    Published: 25 Feb 2009
    7.5
    High

    CVE-2008-6281

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Bluo CMS 1.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 25 Feb 2009
    6.5
    Medium

    CVE-2008-6282

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in engine/users/users_edit_pub.inc in CMS Ortus 1.13 and earlier allows remote authenticated users to execute arbitrary SQL commands via the city parameter in a users_edit_pub action to index.php.

    Published: 25 Feb 2009
    4.3
    Medium

    CVE-2008-6283

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Subtext 2.0 allows remote attackers to inject arbitrary web script or HTML via a comment, related to "the feature which converts URLs to anchor tags."

    Published: 25 Feb 2009
    7.5
    High

    CVE-2008-6284

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in edit.php in Z1Exchange 1.0 allows remote attackers to execute arbitrary SQL commands via the site parameter.

    Published: 25 Feb 2009
    4.3
    Medium

    CVE-2008-6278

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in product.php in RakhiSoftware Price Comparison Script (aka Shopping Cart) allow remote attackers to inject arbitrary web script or HTML via the (1) category_id and (2) subcategory_id parameters.

    Published: 25 Feb 2009
    7.5
    High

    CVE-2008-6285

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in PHP TV Portal 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the mid parameter.

    Published: 25 Feb 2009
    6.5
    Medium

    CVE-2008-6276

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in the User Karma module 5.x before 5.x-1.13 and 6.x before 6.x-1.0-beta1, a module for Drupal, allow remote authenticated administrators to execute arbitrary SQL commands via (1) a content type or (2) a voting API value.

    Published: 25 Feb 2009
    7.5
    High

    CVE-2008-6277

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in product.php in RakhiSoftware Price Comparison Script (aka Shopping Cart) allows remote attackers to execute arbitrary SQL commands via the subcategory_id parameter.

    Published: 25 Feb 2009
    7.5
    High

    CVE-2008-6286

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in SubscriberStart.asp in Active Newsletter 4.3 allow remote attackers to execute arbitrary SQL commands via (1) the email parameter (aka username or E-mail field), or (2) the password parameter (aka password field), to (a) Subscriber.asp or (b) start.asp. NOTE: some of these details are obtained from third party information.

    Published: 25 Feb 2009
    7.5
    High

    CVE-2008-6287

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Broadcast Machine 0.1 allow remote attackers to execute arbitrary PHP code via a URL in the baseDir parameter to (1) MySQLController.php, (2) SQLController.php, (3) SetupController.php, (4) VideoController.php, and (5) ViewController.php in controllers/.

    Published: 25 Feb 2009
    7.8
    High

    CVE-2008-6288

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in download.php in Interface Medien ibase 2.03 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter.

    Published: 25 Feb 2009
    2.6
    Low

    CVE-2009-0737

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the web-based installer (config/index.php) in MediaWiki 1.6 before 1.6.12, 1.12 before 1.12.4, and 1.13 before 1.13.4, when the installer is in active use, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 25 Feb 2009
    5.1
    Medium

    CVE-2009-0735

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in lib/classes/message_class.php in Papoo CMS 3.6, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to read and possibly execute arbitrary files via a .. (dot dot) in the pfadhier parameter. NOTE: some of these details are obtained from third party information.

    Published: 25 Feb 2009
    7.5
    High

    CVE-2009-0740

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in login.php in BlueBird Prelease allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) passwd parameters.

    Published: 25 Feb 2009
    4.3
    Medium

    CVE-2009-0736

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Pebble before 2.3.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 25 Feb 2009
    9.3
    Critical

    CVE-2009-0734

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in MultimediaPlayer.exe 6.86.240.7 in Nokia PC Suite 6.86.9.3 allows remote attackers to execute arbitrary code via a long string in a .m3u playlist file.

    Published: 25 Feb 2009
    7.5
    High

    CVE-2009-0738

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in login.php in Auth Php 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) passwd parameters.

    Published: 25 Feb 2009
    7.5
    High

    CVE-2009-0739

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in login.php in MyNews 0.10 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) passwd parameters.

    Published: 25 Feb 2009
    7.5
    High

    CVE-2009-0741

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Login.asp in Craft Silicon Banking@Home 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the LoginName parameter.

    Published: 25 Feb 2009
    7.5
    High

    CVE-2008-6272

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin/index.php in Dragan Mitic Apoll 0.7 beta and 0.7.5 allows remote attackers to execute arbitrary SQL command via the pass parameter.

    Published: 25 Feb 2009
    6
    Medium

    CVE-2008-6273

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in configuration_script.php in MyKtools 3.0 allows remote authenticated administrators to include and execute arbitrary local files via a .. (dot dot) in the langage parameter, a different vulnerability than CVE-2008-4781. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 25 Feb 2009
    9
    Critical

    CVE-2009-0505

    Last Modified: 23 Apr 2026

    The CICS listener in IBM TXSeries for Multiplatforms 6.2 GA waits for a forcepurge acknowledgement from the CICS Application Server (CICSAS) after an eci response timeout, which might allow remote authenticated users to cause a denial of service (forcepurge handling delay), or have unspecified other impact, via vectors involving slow or nonexistent acknowledgement.

    Published: 25 Feb 2009
    6.2
    Medium

    CVE-2009-0506

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in IBM WebSphere Application Server (WAS) 5.1 and 6.0.2 before 6.0.2.33 on z/OS, when CSIv2 Identity Assertion is enabled and Enterprise JavaBeans (EJB) interaction occurs between a WAS 6.1 instance and a WAS pre-6.1 instance, allows local users to have an unknown impact via vectors related to (1) use of the wrong subject and (2) multiple CBIND checks.

    Published: 25 Feb 2009
    4.3
    Medium

    CVE-2009-0540

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Libero 5.3 SP5, and possibly other versions before 5.5 SP1, allows remote attackers to inject arbitrary web script or HTML via the search term field.

    Published: 25 Feb 2009
    4.3
    Medium

    CVE-2009-0541

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Magento 1.2.0 and 1.2.1.1 allow remote attackers to inject arbitrary web script or HTML via (1) the username field in an admin/ request to index.php, possibly related to the login[username] parameter and the app/code/core/Mage/Admin/Model/Session.php login function; (2) the email address field in an admin/index/forgotpassword/ request to index.php, possibly related to the email parameter and the app/code/core/Mage/Adminhtml/controllers/IndexController.php forgotpasswordAction function; or (3) the return parameter to the default URI under downloader/.

    Published: 25 Feb 2009
    8.8
    High

    CVE-2009-0238

    Last Modified: 22 Apr 2026

    Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1; Excel Viewer 2003 Gold and SP3; Excel Viewer; Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1; and Excel in Microsoft Office 2004 and 2008 for Mac allow remote attackers to execute arbitrary code via a crafted Excel document that triggers an access attempt on an invalid object, as exploited in the wild in February 2009 by Trojan.Mdropper.AC.

    Published: 25 Feb 2009
    7.5
    High

    CVE-2008-6266

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in links.php in Appalachian State University phpWebSite allows remote attackers to execute arbitrary SQL commands via the cid parameter in a viewlink action.

    Published: 25 Feb 2009
    4.3
    Medium

    CVE-2008-6267

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in detail.php in Multi Languages WebShop Online 1.02 allows remote attackers to inject arbitrary web script or HTML via the name parameter.

    Published: 25 Feb 2009
    6.8
    Medium

    CVE-2008-6271

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in TBmnetCMS 1.0, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the content parameter.

    Published: 25 Feb 2009
    7.5
    High

    CVE-2008-6268

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in detail.php in WEBBDOMAIN Multi Languages WebShop Online 1.02 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 25 Feb 2009
    7.5
    High

    CVE-2008-6269

    Last Modified: 23 Apr 2026

    Joovili 3.1.4 allows remote attackers to bypass authentication and gain privileges as other users, including the administrator, by setting the (1) session_id, session_logged_in, and session_username cookies for user privileges; (2) session_admin_id, session_admin_username, and session_admin cookies for admin privileges; and (3) session_staff_id, session_staff_username, and session_staff cookies for staff users.

    Published: 25 Feb 2009
    7.5
    High

    CVE-2008-6270

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin/index.php in Dragan Mitic Apoll 0.7 beta and 0.7.5 allows remote attackers to execute arbitrary SQL command via the user parameter.

    Published: 25 Feb 2009