5
    Medium

    CVE-2009-4876

    Last Modified: 11 Apr 2025

    admin/cikkform.php in Netrix CMS 1.0 allows remote attackers to modify arbitrary pages via a direct request using the cid parameter.

    Source:Mr.tro0oqy
    Published:26 May 2010
    6.4
    Medium

    CVE-2009-4874

    Last Modified: 14 Dec 2016

    TalkBack 2.3.14 does not properly restrict access to the edit comment feature (comments.php), which allows remote attackers to modify comments.

    Source:JIKO
    Published:26 May 2010
    10
    Critical

    CVE-2009-4873

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the HTTP server in Rhino Software Serv-U Web Client 9.0.0.5 allows remote attackers to cause a denial of service (server crash) or execute arbitrary code via a long Session cookie.

    Source:Nikolas Rangos
    Published:26 May 2010
    7.5
    High

    CVE-2009-4872

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in globepersonnel_login.asp in Logoshows BBS 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password fields.

    Source:Dns-Team
    Published:10 May 2010
    7.5
    High

    CVE-2009-4871

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in globepersonnel_forum.asp in Logoshows BBS 2.0 allows remote attackers to execute arbitrary SQL commands via the forumid parameter.

    Source:Ruzgarin_Oglu
    Published:10 May 2010
    7.5
    High

    CVE-2009-4870

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in login.php in PHPCityPortal allow remote attackers to execute arbitrary SQL commands via the (1) req_username (aka Username) and (2) req_password (aka Password) parameters. NOTE: some of these details are obtained from third party information.

    Source:CoBRa_21
    Published:10 May 2010
    4.3
    Medium

    CVE-2009-4869

    Last Modified: 30 Aug 2014

    Cross-site scripting (XSS) vulnerability in index.php in Nasim Guest Book 1.2 allows remote attackers to inject arbitrary web script or HTML via the page parameter.

    Source:Moudi
    Published:10 May 2010
    4.3
    Medium

    CVE-2009-4868

    Last Modified: 1 Sept 2014

    Cross-site scripting (XSS) vulnerability in Hitron Soft Answer Me 1.0 allows remote attackers to inject arbitrary web script or HTML via the q_id parameter to the answers script (aka answers.php). NOTE: some of these details are obtained from third party information.

    Source:Moudi
    Published:10 May 2010
    4.3
    Medium

    CVE-2009-4867

    Last Modified: 1 Apr 2017

    Buffer overflow in Tuniac 090517c allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long URL in a .m3u playlist file.

    Source:Dr_IDE
    Published:10 May 2010
    4.3
    Medium

    CVE-2009-4864

    Last Modified: 12 Sept 2014

    Multiple cross-site scripting (XSS) vulnerabilities in escorts_search.php in I-Escorts Directory Script and Agency Script allow remote attackers to inject arbitrary web script or HTML via the (1) search_name and (2) languages parameters. NOTE: some of these details are obtained from third party information.

    Source:599eme Man
    Published:10 May 2010
    9.3
    Critical

    CVE-2009-4863

    Last Modified: 17 Sept 2010

    Stack-based buffer overflow in UltraPlayer Media Player 2.112 allows remote attackers to execute arbitrary code via a long string in a .usk file.

    Source:SarBoT511
    Published:10 May 2010
    7.5
    High

    CVE-2009-4862

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in Alwasel 1.5 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) show.php and (2) xml.php.

    Source:SwEET-DeViL
    Published:10 May 2010
    7.5
    High

    CVE-2009-4860

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in demo.php in Typing Pal 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the idTableProduit parameter.

    Source:Red-D3v1L
    Published:10 May 2010
    4.3
    Medium

    CVE-2009-4858

    Last Modified: 30 Aug 2014

    Cross-site scripting (XSS) vulnerability in questiondetail.php in Yahoo Answers Clone allows remote attackers to inject arbitrary web script or HTML via the questionid parameter.

    Source:Moudi
    Published:10 May 2010
    4.3
    Medium

    CVE-2009-4857

    Last Modified: 2 Oct 2014

    Cross-site scripting (XSS) vulnerability in login.php in PHP Photo Vote 1.3F allows remote attackers to inject arbitrary web script or HTML via the page parameter.

    Source:Moudi
    Published:10 May 2010
    4.3
    Medium

    CVE-2009-4856

    Last Modified: 2 Oct 2014

    Cross-site scripting (XSS) vulnerability in subitems.php in PHP Easy Shopping Cart 3.1R allows remote attackers to inject arbitrary web script or HTML via the name parameter.

    Source:Moudi
    Published:10 May 2010
    7.5
    High

    CVE-2009-4855

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in TYPO3 4.0 allows remote attackers to execute arbitrary SQL commands via the showUid parameter. NOTE: the TYPO3 Security Team disputes this report, stating that "there is no such vulnerability... The showUid parameter is generally used in third-party TYPO3 extensions - not in TYPO3 Core.

    Source:Ro0T-MaFia
    Published:10 May 2010
    7.5
    High

    CVE-2009-4854

    Last Modified: 14 Dec 2016

    addons/import.php in TalkBack 2.3.14 allows remote attackers to execute arbitrary commands via the result parameter.

    Source:JIKO
    Published:7 May 2010
    9.3
    Critical

    CVE-2009-4850

    Last Modified: 10 Mar 2011

    The Awingsoft Awakening Winds3D Viewer plugin 3.5.0.9 allows remote attackers to execute arbitrary programs via a SceneURL property value with a URL for a .exe file.

    Source:Metasploit
    Published:7 May 2010
    6.8
    Medium

    CVE-2009-4849

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in ToutVirtual VirtualIQ Pro 3.2 build 7882 and 3.5 build 8691 allow remote attackers to hijack the authentication of administrators for requests that (1) create a new user account via a save action to tvserver/user/user.do, (2) shutdown a virtual machine, (3) start a virtual machine, (4) restart a virtual machine, or (5) schedule an activity.

    Source:Alberto Trivero
    Published:7 May 2010
    9.3
    Critical

    CVE-2009-4841

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in the SonicMediaPlayer ActiveX control in SonicMediaPlayer.dll in Roxio CinePlayer 3.2 allows remote attackers to execute arbitrary code via a long argument to the DiskType method. NOTE: this might overlap CVE-2007-1559.

    Source:snakespc
    Published:5 May 2010
    9.3
    Critical

    CVE-2009-4840

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in the IAManager ActiveX control in IAManager.dll in Roxio CinePlayer 3.2 allows remote attackers to execute arbitrary code via a long argument to the SetIAPlayerName method.

    Source:His0k4
    Published:5 May 2010
    7.5
    High

    CVE-2009-4836

    Last Modified: 11 Apr 2025

    Eval injection vulnerability in system/services/init.php in Movie PHP Script 2.0 allows remote attackers to execute arbitrary PHP code via the anticode parameter.

    Source:SirGod
    Published:5 May 2010
    6.8
    Medium

    CVE-2009-4834

    Last Modified: 11 Apr 2025

    lib.php in Zeroboard 4.1 pl7 allows remote attackers to execute arbitrary PHP code via a crafted parameter name, possibly related to now_connect.php.

    Source:SpeeDr00t
    Published:4 May 2010
    7.2
    High

    CVE-2009-4832

    Last Modified: 11 Apr 2025

    The dlpcrypt.sys kernel driver 0.1.1.27 in DESlock+ 4.0.2 allows local users to gain privileges via a crafted IOCTL 0x80012010 request to the DLPCryptCore device.

    Source:mu-b
    Published:29 Apr 2010
    6.8
    Medium

    CVE-2009-4828

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in administration/admins.php in Ad Manager Pro (aka AdManagerPro) 3.0 allows remote attackers to hijack the authentication of administrators for requests that create new administrative users via an admin_created action. NOTE: some of these details are obtained from third party information.

    Source:bi0
    Published:27 Apr 2010
    6.8
    Medium

    CVE-2009-4827

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in admin.php in Mail Manager Pro allows remote attackers to hijack the authentication of administrators for requests that change the admin password via a change action.

    Source:Milos Zivanovic
    Published:27 Apr 2010
    6.8
    Medium

    CVE-2009-4826

    Last Modified: 12 Jul 2015

    Cross-site request forgery (CSRF) vulnerability in hosting/admin_ac.php in ScriptsEz Mini Hosting Panel allows remote attackers to hijack the authentication of administrators for requests that alter administrative settings via a cp action.

    Source:Milos Zivanovic
    Published:27 Apr 2010
    5
    Medium

    CVE-2009-4825

    Last Modified: 11 Apr 2025

    8pixel.net Blog 4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for App_Data/sb.mdb.

    Source:LionTurk
    Published:27 Apr 2010
    4.3
    Medium

    CVE-2009-4823

    Last Modified: 19 May 2014

    Cross-site scripting (XSS) vulnerability in frontend/x3/files/fileop.html in cPanel 11.0 through 11.24.7 allows remote attackers to inject arbitrary web script or HTML via the fileop parameter.

    Source:RENO
    Published:27 Apr 2010
    4.3
    Medium

    CVE-2009-4822

    Last Modified: 19 May 2014

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in Kasseler CMS 1.3.4 allow remote attackers to inject arbitrary web script or HTML via the (1) do, (2) id, and (3) uname parameters.

    Source:Gamoscu
    Published:27 Apr 2010
    5
    Medium

    CVE-2009-4820

    Last Modified: 11 Apr 2025

    Angelo-Emlak 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for veribaze/angelo.mdb.

    Source:LionTurk
    Published:27 Apr 2010
    6.8
    Medium

    CVE-2009-4819

    Last Modified: 11 Apr 2025

    Multiple unrestricted file upload vulnerabilities in upload.php in PHPhotoalbum allow remote attackers to execute arbitrary code by uploading a file with a (1) .php.pgif or (2) .php.pjpeg double extension, then accessing it via a direct request to the file in albums/userpics/.

    Source:wlhaan hacker
    Published:27 Apr 2010
    6.8
    Medium

    CVE-2009-4818

    Last Modified: 11 Apr 2025

    Unrestricted file upload vulnerability in upload.php in PHPSimplicity Simplicity oF Upload 1.3.2 allows remote attackers to execute arbitrary PHP code by uploading a file with a double extension, as demonstrated by .php.gif.

    Source:Master Mind
    Published:27 Apr 2010
    6.8
    Medium

    CVE-2009-4817

    Last Modified: 11 Apr 2025

    Unrestricted file upload vulnerability in Element-IT Ultimate Uploader 1.3 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in upload/.

    Source:Master Mind
    Published:27 Apr 2010
    5
    Medium

    CVE-2009-4816

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in api/download_checker.php in MegaLab The Uploader 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter.

    Source:Stack
    Published:27 Apr 2010
    4.3
    Medium

    CVE-2009-4814

    Last Modified: 20 May 2014

    Cross-site scripting (XSS) vulnerability in Wolfram Research webMathematica allows remote attackers to inject arbitrary web script or HTML via the URI to the MSP script.

    Source:Floyd Fuh
    Published:27 Apr 2010
    4.3
    Medium

    CVE-2009-4813

    Last Modified: 20 May 2014

    Cross-site scripting (XSS) vulnerability in myps.php in MyBB (aka MyBulletinBoard) 1.4.10 allows remote attackers to inject arbitrary web script or HTML via the username parameter in a donate action.

    Source:Steven Abbagnaro
    Published:27 Apr 2010
    5
    Medium

    CVE-2009-4809

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in thumbnail.ghp in Easy File Sharing (EFS) Web Server 4.8 allows remote attackers to read arbitrary files via a .. (dot dot) in the vfolder parameter.

    Source:Stack
    Published:23 Apr 2010
    7.5
    High

    CVE-2009-4808

    Last Modified: 30 Dec 2016

    admin.php in Graugon PHP Article Publisher 1.0 allows remote attackers to bypass authentication and obtain administrative access by setting the g_admin cookie to 1.

    Source:x0r
    Published:23 Apr 2010
    7.5
    High

    CVE-2009-4807

    Last Modified: 30 Dec 2016

    Multiple SQL injection vulnerabilities in Graugon PHP Article Publisher 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) c parameter to index.php and the (2) id parameter to view.php.

    Source:x0r
    Published:23 Apr 2010
    7.5
    High

    CVE-2009-4806

    Last Modified: 11 Apr 2025

    admin/save_user.asp in Digital Interchange Document Library 1.0.1 does not require administrative authentication, which allows remote attackers to read or modify the administrator's credentials via unspecified vectors. NOTE: some of these details are obtained from third party information.

    Source:ByALBAYX
    Published:23 Apr 2010
    6.8
    Medium

    CVE-2009-4805

    Last Modified: 17 Feb 2017

    Multiple SQL injection vulnerabilities in EZ-Blog Beta 1, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via (1) the storyid parameter to public/view.php or (2) the kill parameter to admin/remove.php.

    Source:Salvatore Fresta
    Published:23 Apr 2010
    7.5
    High

    CVE-2009-4801

    Last Modified: 17 Feb 2017

    EZ-Blog Beta 1 does not require authentication, which allows remote attackers to create or delete arbitrary posts via requests to PHP scripts.

    Source:Salvatore Fresta
    Published:23 Apr 2010
    4
    Medium

    CVE-2009-4800

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in Sysax Multi Server 4.3 and 4.5 allows remote authenticated users to delete arbitrary files via a ..// (dot dot slash slash) in a DELE command.

    Source:Jonathan Salwan
    Published:22 Apr 2010
    5
    Medium

    CVE-2009-4799

    Last Modified: 11 Apr 2025

    Diskos CMS 6.x stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for (1) artikler_prod.mdb or (2) medlemmer.mdb.

    Source:AnGeL25dZ
    Published:22 Apr 2010
    7.5
    High

    CVE-2009-4798

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in Diskos CMS 6.x allow remote attackers to execute arbitrary SQL commands via the (1) kat parameter to side.asp, and the (2) brugerid and (3) password fields to the administration login feature.

    Source:AnGeL25dZ
    Published:22 Apr 2010
    7.5
    High

    CVE-2009-4797

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in browse.php in JobHut 1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the pk parameter.

    Source:K-159
    Published:22 Apr 2010
    7.5
    High

    CVE-2009-4796

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in the ExecuteQueries function in private/system/classes/listfactory.class.php in glFusion 1.1.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) order and (2) direction parameters to search.php.

    Source:Nine:Situations:Group
    Published:22 Apr 2010
    6.8
    Medium

    CVE-2009-4795

    Last Modified: 15 Apr 2014

    Multiple SQL injection vulnerabilities in Xlight FTP Server before 3.2.1, when ODBC authentication is enabled, allow remote attackers to execute arbitrary SQL commands via the (1) USER (aka username) or (2) PASS (aka password) command.

    Source:fla
    Published:22 Apr 2010