7.2
    High

    CVE-2009-5068

    Last Modified: 18 Dec 2016

    There is a file disclosure vulnerability in SMF (Simple Machines Forum) affecting versions through v2.0.3. On some configurations a SMF deployment is shared by several "co-admins" that are not trusted beyond the SMF deployment. This vulnerability allows them to read arbitrary files on the filesystem and therefore gain new privileges by reading the settings.php with the database passwords.

    Source:SimpleAudit Team
    Published:15 Jan 2020
    4.3
    Medium

    CVE-2009-5067

    Last Modified: 24 Oct 2016

    Directory traversal vulnerability in html2ps before 1.0b6 allows remote attackers to read arbitrary files via a .. (dot dot) in the "include file" SSI directive. NOTE: this issue only might be a vulnerability in limited scenarios, such as if html2ps is invoked by a web application, or if a user-assisted attacker provides filenames whose contents could cause a denial of service, such as certain devices.

    Source:epiphant
    Published:27 Sept 2009
    4.3
    Medium

    CVE-2009-5065

    Last Modified: 18 Dec 2014

    Cross-site scripting (XSS) vulnerability in feedparser.py in Universal Feed Parser (aka feedparser or python-feedparser) before 5.0 allows remote attackers to inject arbitrary web script or HTML via vectors involving nested CDATA stanzas.

    Source:fazalmajid
    Published:11 Apr 2011
    6.8
    Medium

    CVE-2009-5029

    Last Modified: 16 Mar 2015

    Integer overflow in the __tzfile_read function in glibc before 2.15 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted timezone (TZ) file, as demonstrated using vsftpd.

    Source:dividead
    Published:1 Jun 2009
    6.8
    Medium

    CVE-2009-5026

    Last Modified: 26 Sept 2014

    The executable comment feature in MySQL 5.0.x before 5.0.93 and 5.1.x before 5.1.50, when running in certain slave configurations in which the slave is running a newer version than the master, allows remote attackers to execute arbitrary SQL commands via custom comments.

    Source:Libing Song
    Published:17 Aug 2012
    6.8
    Medium

    CVE-2009-5022

    Last Modified: 31 Oct 2016

    Heap-based buffer overflow in tif_ojpeg.c in the OJPEG decoder in LibTIFF before 3.9.5 allows remote attackers to execute arbitrary code via a crafted TIFF file.

    Source:Francis Provencher
    Published:9 Feb 2009
    5
    Medium

    CVE-2009-5019

    Last Modified: 11 Apr 2025

    Web Wiz NewsPad stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for database/NewsPad.mdb.

    Source:ViRuSMaN
    Published:1 Dec 2010
    6.8
    Medium

    CVE-2009-5018

    Last Modified: 17 Aug 2014

    Stack-based buffer overflow in gif2png.c in gif2png 2.5.3 and earlier might allow context-dependent attackers to execute arbitrary code via a long command-line argument, as demonstrated by a CGI program that launches gif2png.

    Source:Razuel Akaharnath
    Published:14 Oct 2009
    7.5
    High

    CVE-2009-5003

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in click.php in e-soft24 Banner Exchange Script 1.0 allows remote attackers to execute arbitrary SQL commands via the targetid parameter.

    Source:599eme Man
    Published:22 Sept 2010
    7.5
    High

    CVE-2009-4993

    Last Modified: 11 Apr 2025

    PHP remote file inclusion vulnerability in home.php in LM Starmail Paidmail 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.

    Source:int_main();
    Published:25 Aug 2010
    7.5
    High

    CVE-2009-4992

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in paidbanner.php in LM Starmail Paidmail 2.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.

    Source:int_main();
    Published:25 Aug 2010
    4.3
    Medium

    CVE-2009-4991

    Last Modified: 11 Sept 2014

    Cross-site scripting (XSS) vulnerability in users/resume_register.php in Omnistar Recruiting allows remote attackers to inject arbitrary web script or HTML via the job2 parameter.

    Source:MizoZ
    Published:25 Aug 2010
    4.3
    Medium

    CVE-2009-4989

    Last Modified: 3 May 2014

    Cross-site scripting (XSS) vulnerability in index.php in AJ Auction Pro OOPD 3.0 allows remote attackers to inject arbitrary web script or HTML via the txtkeyword parameter in a search action.

    Source:599eme Man
    Published:25 Aug 2010
    10
    Critical

    CVE-2009-4988

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in NT_Naming_Service.exe in SAP Business One 2005 A 6.80.123 and 6.80.320 allows remote attackers to execute arbitrary code via a long GIOP request to TCP port 30000.

    Source:Bruk0ut
    Published:25 Aug 2010
    7.5
    High

    CVE-2009-4987

    Last Modified: 11 Apr 2025

    admin/header.php in Scripteen Free Image Hosting Script 2.3 allows remote attackers to bypass authentication and gain administrative access by setting the cookgid cookie value to 1, a different vector than CVE-2008-3211.

    Source:Qabandi
    Published:25 Aug 2010
    6.8
    Medium

    CVE-2009-4986

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in index.php in In-Portal 4.3.1, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the env parameter.

    Source:Angela Chang
    Published:25 Aug 2010
    7.5
    High

    CVE-2009-4985

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in browse.php in Accessories Me PHP Affiliate Script 1.4 allows remote attackers to execute arbitrary SQL commands via the Go parameter.

    Source:Moudi
    Published:25 Aug 2010
    4.3
    Medium

    CVE-2009-4984

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Accessories Me PHP Affiliate Script 1.4 allow remote attackers to inject arbitrary web script or HTML via the (1) Keywords parameter to search.php and (2) SearchIndex parameter to browse.php.

    Source:Moudi
    Published:25 Aug 2010
    4.3
    Medium

    CVE-2009-4983

    Last Modified: 13 Sept 2014

    Multiple cross-site scripting (XSS) vulnerabilities in Silurus Classifieds 1.0 allow remote attackers to inject arbitrary web script or HTML via the ID parameter to (1) category.php and (2) wcategory.php, and the (3) keywords parameter to search.php.

    Source:Moudi
    Published:25 Aug 2010
    6.8
    Medium

    CVE-2009-4982

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the select function in Irokez CMS 0.7.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the PATH_INFO to the default URI.

    Source:Ins3t
    Published:25 Aug 2010
    5
    Medium

    CVE-2009-4978

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in down.php in MyBackup 1.4.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter.

    Source:SirGod
    Published:25 Aug 2010
    6.5
    Medium

    CVE-2009-4977

    Last Modified: 11 Apr 2025

    PHP remote file inclusion vulnerability in index.php in MyBackup 1.4.0 allows remote authenticated users to execute arbitrary PHP code via a URL in the main_content parameter.

    Source:SirGod
    Published:25 Aug 2010
    7.5
    High

    CVE-2009-4974

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in box_display.php in TotalCalendar 2.4 allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the box parameter.

    Source:Moudi
    Published:27 Jul 2010
    7.5
    High

    CVE-2009-4973

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in rss.php in TotalCalendar 2.4 allows remote attackers to execute arbitrary SQL commands via the selectedCal parameter in a SwitchCal action.

    Source:Moudi
    Published:27 Jul 2010
    9.3
    Critical

    CVE-2009-4964

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in KSP 2006 FINAL allows remote attackers to execute arbitrary code via a long string in a .M3U playlist file.

    Source:hack4love
    Published:27 Jul 2010
    9.3
    Critical

    CVE-2009-4962

    Last Modified: 10 Aug 2010

    Stack-based buffer overflow in Fat Player 0.6b allows remote attackers to execute arbitrary code via a long string in a .wav file. NOTE: some of these details are obtained from third party information.

    Source:Praveen Darshanam
    Published:27 Jul 2010
    5
    Medium

    CVE-2009-4961

    Last Modified: 11 Apr 2025

    Lanai Core 0.6 allows remote attackers to obtain configuration information via a direct request to info.php, which calls the phpinfo function.

    Source:Khashayar Fereidani
    Published:27 Jul 2010
    7.5
    High

    CVE-2009-4958

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in video.php in EMO Breeder Manager (aka EMO Breader Manager) allows remote attackers to execute arbitrary SQL commands via the idd parameter.

    Source:Mr.SQL
    Published:27 Jul 2010
    7.5
    High

    CVE-2009-4957

    Last Modified: 29 Nov 2016

    Directory traversal vulnerability in loadpanel.php in Interspire ActiveKB allows remote attackers to read arbitrary files and possibly have unspecified other impact via directory traversal sequences in the Panel parameter.

    Source:Angela Chang
    Published:22 Jul 2010
    7.5
    High

    CVE-2009-4940

    Last Modified: 3 Sept 2021

    SQL injection vulnerability in index.php in Zeus Cart 2.3 and earlier allows remote attackers to execute arbitrary SQL commands via the maincatid parameter in a showmaincatlanding action.

    Source:Br0ly
    Published:22 Jul 2010
    4.3
    Medium

    CVE-2009-4939

    Last Modified: 27 Oct 2016

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in AdPeeps 8.5d1 allow remote attackers to inject arbitrary web script or HTML via the (1) uid parameter, (2) uid parameter in a login_lookup action, (3) uid parameter in an adminlogin action, (4) campaignid parameter in a createcampaign action, (5) type parameter in a view_account_stats action, (6) period parameter in a view_account_stats action, (7) uid parameter in a view_adrates action, (8) accname parameter in an account_confirmation action, (9) loginpass parameter in an account_confirmation action, (10) e9 parameter in a setup_account action, (11) from parameter in an email_advertisers action, (12) message parameter in an email_advertisers action, (13) idno parameter in an edit_ad_package action, (14) Advertiser Name field, (15) First Name field, (16) Last Name field, (17) Address field, (18) Phone Number field, (19) Password Hint field, or (20) URL field; and (21) allow remote authenticated users to inject arbitrary web script or HTML via an unspecified form associated with a view_adrates action.

    Source:Matt
    Published:22 Jul 2010
    7.5
    High

    CVE-2009-4936

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in Small Pirate (SPirate) 2.1 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to the default URI in an rss .xml action, or the id parameter to (2) pag1.php, (3) pag1-guest.php, (4) rss-comment_post.php (aka rss-coment_post.php), or (5) rss-pic-comment.php.

    Source:YEnH4ckEr
    Published:22 Jul 2010
    7.5
    High

    CVE-2009-4935

    Last Modified: 27 Oct 2016

    SQL injection vulnerability in ogp_show.php in Online Guestbook Pro allows remote attackers to execute arbitrary SQL commands via the display parameter.

    Source:Hussin X
    Published:9 Jul 2010
    4.3
    Medium

    CVE-2009-4934

    Last Modified: 18 Apr 2014

    Cross-site scripting (XSS) vulnerability in index.php in Online Photo Pro 2.0 allows remote attackers to inject arbitrary web script or HTML via the section parameter.

    Source:Vrs-hCk
    Published:9 Jul 2010
    7.5
    High

    CVE-2009-4933

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in login.php in EZ Webitor allow remote attackers to execute arbitrary SQL commands via the (1) txtUserId (Username) and (2) txtPassword (Password) parameters. NOTE: some of these details are obtained from third party information.

    Source:snakespc
    Published:9 Jul 2010
    6.8
    Medium

    CVE-2009-4932

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in 1by1 1.67 (aka 1.6.7.0) allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long string in a .m3u playlist file.

    Source:GoLd_M
    Published:9 Jul 2010
    7.5
    High

    CVE-2009-4929

    Last Modified: 11 Apr 2025

    admin/manage_users.php in TotalCalendar 2.4 does not require administrative authentication, which allows remote attackers to change arbitrary passwords via the newPW1 and newPW2 parameters.

    Source:ThE g0bL!N
    Published:9 Jul 2010
    7.5
    High

    CVE-2009-4927

    Last Modified: 11 Apr 2025

    WB News 2.1.2 allows remote attackers to bypass authentication and gain administrative access via a modified WBNEWS cookie, as demonstrated by setting this cookie to 1.

    Source:ThE g0bL!N
    Published:9 Jul 2010
    4.3
    Medium

    CVE-2009-4926

    Last Modified: 18 Apr 2014

    Multiple cross-site scripting (XSS) vulnerabilities in Online Contact Manager (formerly EContact PRO) 3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) showGroup parameter to (a) index.php and the (2) id parameter to (b) view.php, (c) email.php, (d) edit.php, and (e) delete.php.

    Source:Vrs-hCk
    Published:9 Jul 2010
    6.8
    Medium

    CVE-2009-4925

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in Portale e-commerce Creasito (aka creasito e-commerce content manager) 1.3.16, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the username parameter to (1) admin/checkuser.php and (2) checkuser.php.

    Source:Salvatore Fresta
    Published:9 Jul 2010
    4.3
    Medium

    CVE-2009-4908

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in oBlog allow remote attackers to inject arbitrary web script or HTML via the (1) commentName, (2) commentEmail, (3) commentWeb, or (4) commentText parameter to article.php; and allow remote authenticated administrators to inject arbitrary web script or HTML via the (5) article_id or (6) title parameter to admin/write.php, the (7) category_id or (8) category_name parameter to admin/groups.php, the (9) blogroll_id or (10) title parameter to admin/blogroll.php, or the (11) blog_name or (12) tag_line parameter to admin/settings.php.

    Source:Milos Zivanovic
    Published:25 Jun 2010
    6.8
    Medium

    CVE-2009-4907

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in oBlog allow remote attackers to hijack the authentication of administrators for requests that (1) change the admin password, (2) force an admin logout, (3) change the visibility of posts, (4) remove links, and (5) change the name fields of a blog.

    Source:Milos Zivanovic
    Published:25 Jun 2010
    6.8
    Medium

    CVE-2009-4906

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in index.php in Acc PHP eMail 1.1 allows remote attackers to hijack the authentication of administrators for requests that change passwords.

    Source:bi0
    Published:25 Jun 2010
    6.8
    Medium

    CVE-2009-4905

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in index.php in Acc Statistics 1.1 allow remote attackers to hijack the authentication of administrators for requests that change (1) passwords, (2) usernames, and (3) e-mail addresses.

    Source:Milos Zivanovic
    Published:25 Jun 2010
    7.5
    High

    CVE-2009-4892

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in Content Management System WEBjump! allows remote attackers to execute arbitrary SQL commands via the id parameter to (1) portfolio_genre.php and (2) news_id.php.

    Source:M3NW5
    Published:11 Jun 2010
    7.5
    High

    CVE-2009-4889

    Last Modified: 22 Nov 2016

    SQL injection vulnerability in books.php in the Book Panel (book_panel) module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the bookid parameter.

    Source:elusiven
    Published:11 Jun 2010
    4.3
    Medium

    CVE-2009-4888

    Last Modified: 14 Apr 2014

    Cross-site scripting (XSS) vulnerability in poster.php in PHortail 1.2.1 allows remote attackers to inject arbitrary web script or HTML via the (1) pseudo, (2) email, (3) ti, and (4) txt parameters.

    Source:Jonathan Salwan
    Published:11 Jun 2010
    5
    Medium

    CVE-2009-4886

    Last Modified: 11 Apr 2025

    Multiple directory traversal vulnerabilities in phpCommunity 2 2.1.8 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) file parameter to module/admin/files/show_file.php and the (2) path parameter to module/admin/files/show_source.php.

    Source:Salvatore Fresta
    Published:11 Jun 2010
    7.5
    High

    CVE-2009-4883

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in PHPRecipeBook 2.24 and 2.39 allows remote attackers to execute arbitrary SQL commands via the (1) base_id or (2) course_id parameter in a search action.

    Source:d3b4g
    Published:11 Jun 2010
    5
    Medium

    CVE-2009-4880

    Last Modified: 8 May 2014

    Multiple integer overflows in the strfmon implementation in the GNU C Library (aka glibc or libc6) 2.10.1 and earlier allow context-dependent attackers to cause a denial of service (memory consumption or application crash) via a crafted format string, as demonstrated by a crafted first argument to the money_format function in PHP, a related issue to CVE-2008-1391.

    Source:Maksymilian Arciemowicz
    Published:3 Sept 2009