7.5
    High

    CVE-2009-4794

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in Community CMS 0.5 allow remote attackers to execute arbitrary SQL commands via the (1) article_id parameter to view.php and the (2) a parameter in an event action to calendar.php, reachable through index.php.

    Source:Salvatore Fresta
    Published:22 Apr 2010
    6
    Medium

    CVE-2009-4793

    Last Modified: 21 Dec 2016

    Unrestricted file upload vulnerability in adminpanel/scripts/addphotos.php in BandSite CMS 1.1.4 allows remote authenticated administrators to execute arbitrary PHP code by uploading a file with an executable extension via an addphotos action to adminpanel/index.php, and then accessing the file via a direct request with an images/gallery/ directory name. NOTE: some of these details are obtained from third party information.

    Source:SirGod
    Published:22 Apr 2010
    7.5
    High

    CVE-2009-4792

    Last Modified: 21 Dec 2016

    SQL injection vulnerability in includes/content/member_content.php in BandSite CMS 1.1.4 allows remote attackers to execute arbitrary SQL commands via the memid parameter to members.php.

    Source:SirGod
    Published:22 Apr 2010
    7.5
    High

    CVE-2009-4791

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in Family Connections (aka FCMS) before 1.8.2 allow remote attackers to execute arbitrary SQL commands via the (1) letter parameter to addressbook.php, (2) id parameter to recipes.php, (3) year parameter to register.php, (4) poll_id parameter to home.php, and (5) email parameter to lostpw.php.

    Source:Salvatore Fresta
    Published:22 Apr 2010
    9
    Critical

    CVE-2009-4790

    Last Modified: 11 Apr 2025

    Multiple directory traversal vulnerabilities in Sysax Multi Server 4.5 allow remote authenticated users to read or modify arbitrary files via crafted FTP commands. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Jonathan Salwan
    Published:22 Apr 2010
    7.5
    High

    CVE-2009-4789

    Last Modified: 11 Apr 2025

    Multiple PHP remote file inclusion vulnerabilities in the MojoBlog component RC 0.15 for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) wp-comments-post.php and (2) wp-trackback.php.

    Source:kaMtiEz
    Published:21 Apr 2010
    7.5
    High

    CVE-2009-4785

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Quick News (com_quicknews) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the newsid parameter in a view_item action to index.php.

    Source:Don Tukulesto
    Published:21 Apr 2010
    7.5
    High

    CVE-2009-4784

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Joaktree (com_joaktree) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the treeId parameter to index.php.

    Source:Don Tukulesto
    Published:21 Apr 2010
    7.5
    High

    CVE-2009-4783

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in Theeta CMS, possibly 0.01, allow remote attackers to execute arbitrary SQL commands via the start parameter to (1) forum.php and (2) thread.php in community/, and (3) blog/index.php.

    Source:c0dy
    Published:21 Apr 2010
    4.3
    Medium

    CVE-2009-4782

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Theeta CMS, possibly 0.01, allow remote attackers to inject arbitrary web script or HTML via the (1) start, (2) forum, and (3) cat parameters to community/thread.php; (4) start and (5) cat parameters to community/forum.php; and (6) start parameter to blog/index.php.

    Source:c0dy
    Published:21 Apr 2010
    7.2
    High

    CVE-2009-4781

    Last Modified: 11 Apr 2025

    TUKEVA Password Reminder before 1.0.0.4 uses a hard-coded password for rem.accdb, which allows local users to discover credentials via a DBI connection.

    Source:iqlusion
    Published:21 Apr 2010
    4.3
    Medium

    CVE-2009-4780

    Last Modified: 27 Sept 2016

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in phpMyFAQ before 2.5.5 allow remote attackers to inject arbitrary web script or HTML via (1) the lang parameter in a sitemap action, (2) the search parameter in a search action, (3) the tagging_id parameter in a search action, (4) the highlight parameter in an artikel action, (5) the artlang parameter in an artikel action, (6) the letter parameter in a sitemap action, (7) the lang parameter in a show action, (8) the cat parameter in a show action, (9) the newslang parameter in a news action, (10) the artlang parameter in a send2friend action, (11) the cat parameter in a send2friend action, (12) the id parameter in a send2friend action, (13) the srclang parameter in a translate action, (14) the id parameter in a translate action, (15) the cat parameter in a translate action, (16) the cat parameter in an add action, or (17) the question parameter in an add action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Amol Naik
    Published:21 Apr 2010
    7.5
    High

    CVE-2009-4779

    Last Modified: 11 Apr 2025

    Multiple PHP remote file inclusion vulnerabilities in NukeHall 0.3 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the spaw_root parameter to (1) blocks.php, (2) messages.php, and (3) stories.php in admin/modules/.

    Source:cr4wl3r
    Published:21 Apr 2010
    4.3
    Medium

    CVE-2009-4775

    Last Modified: 11 Apr 2025

    Format string vulnerability in Ipswitch WS_FTP Professional 12 before 12.2 allows remote attackers to cause a denial of service (crash) via format string specifiers in the status code portion of an HTTP response.

    Source:Jeremy Brown
    Published:21 Apr 2010
    9.3
    Critical

    CVE-2009-4769

    Last Modified: 29 Sept 2016

    Multiple format string vulnerabilities in the tolog function in httpdx 1.4, 1.4.5, 1.4.6, 1.4.6b, and 1.5 allow (1) remote attackers to execute arbitrary code via format string specifiers in a GET request to the HTTP server component when logging is enabled, and allow (2) remote authenticated users to execute arbitrary code via format string specifiers in a PWD command to the FTP server component.

    Source:Metasploit
    Published:20 Apr 2010
    4.3
    Medium

    CVE-2009-4767

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in Plohni Shoutbox 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) input_name and (2) input_text parameters. NOTE: some of these details are obtained from third party information.

    Source:SkuLL-HackeR
    Published:20 Apr 2010
    9.3
    Critical

    CVE-2009-4761

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in Mini-stream RM Downloader allows remote attackers to execute arbitrary code via a long string in a .smi file.

    Source:Stack
    Published:29 Mar 2010
    5
    Medium

    CVE-2009-4760

    Last Modified: 11 Apr 2025

    Winn ASP Guestbook 1.01 Beta stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for data/guestbook.mdb.

    Source:ZoRLu
    Published:29 Mar 2010
    9.3
    Critical

    CVE-2009-4759

    Last Modified: 11 Apr 2025

    Buffer overflow in BrotherSoft BMXPlay 0.4.4b allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long string in a .BMX file.

    Source:SirGod
    Published:29 Mar 2010
    9.3
    Critical

    CVE-2009-4758

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in dicas Mpegable Player 2.12 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long string in a .YUV file.

    Source:GoLd_M
    Published:29 Mar 2010
    9.3
    Critical

    CVE-2009-4757

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in BrotherSoft EW-MusicPlayer 0.8 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long string in a malformed playlist (.m3u) file. NOTE: some of these details are obtained from third party information.

    Source:SirGod
    Published:29 Mar 2010
    9.3
    Critical

    CVE-2009-4756

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in TraktorBeatport.exe 1.0.0.283 in Beatport Player 1.0.0.0 allows remote attackers to execute arbitrary code via a long string in a malformed playlist (.m3u) file.

    Source:SirGod
    Published:29 Mar 2010
    9.3
    Critical

    CVE-2009-4755

    Last Modified: 11 Apr 2025

    Multiple stack-based buffer overflows in Mercury Audio Player 1.21 allow remote attackers to execute arbitrary code via a long string in a malformed (1) .b4s or (2) .pls playlist file.

    Source:His0k4
    Published:29 Mar 2010
    9.3
    Critical

    CVE-2009-4754

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in Mercury Audio Player 1.21 allows remote attackers to execute arbitrary code via a long string in a malformed playlist (.m3u) file.

    Source:SirGod
    Published:29 Mar 2010
    7.1
    High

    CVE-2009-4753

    Last Modified: 11 Apr 2025

    Multiple buffer overflows in the FTP server on the Addonics NAS Adapter NASU2FW41 with loader 1.17 allow remote attackers to cause a denial of service (TCP/IP outage) via long arguments to the (1) XRMD, (2) delete, (3) RNFR, or (4) RNTO command.

    Source:h00die
    Published:29 Mar 2010
    7.5
    High

    CVE-2009-4752

    Last Modified: 26 Sept 2014

    PHP remote file inclusion vulnerability in anzeiger/start.php in Swinger Club Portal allows remote attackers to execute arbitrary PHP code via a URL in the go parameter.

    Source:Moudi
    Published:26 Mar 2010
    7.5
    High

    CVE-2009-4751

    Last Modified: 26 Sept 2014

    SQL injection vulnerability in anzeiger/start.php in Swinger Club Portal allows remote attackers to execute arbitrary SQL commands via the id parameter in a rubrik action.

    Source:Moudi
    Published:26 Mar 2010
    6.8
    Medium

    CVE-2009-4750

    Last Modified: 26 Sept 2014

    PHP remote file inclusion vulnerability in home.php in Top Paidmailer allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.

    Source:Moudi
    Published:26 Mar 2010
    7.5
    High

    CVE-2009-4749

    Last Modified: 11 Nov 2016

    Multiple SQL injection vulnerabilities in PHP Live! 3.2.1 and 3.2.2 allow remote attackers to execute arbitrary SQL commands via the x parameter to (1) message_box.php and (2) request.php.

    Source:boom3rang
    Published:26 Mar 2010
    7.5
    High

    CVE-2009-4748

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in mycategoryorder.php in the My Category Order plugin 2.8 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the parentID parameter in an act_OrderCategories action to wp-admin/post-new.php.

    Source:Manh Luat
    Published:26 Mar 2010
    7.5
    High

    CVE-2009-4747

    Last Modified: 5 Sept 2016

    PHP remote file inclusion vulnerability in public/code/cp_html2xhtmlbasic.php in All In One Control Panel (AIOCP) 1.4.001 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter, a different vector than CVE-2009-3220.

    Source:Hadi Kiamarsi
    Published:26 Mar 2010
    4.3
    Medium

    CVE-2009-4746

    Last Modified: 15 Nov 2017

    Cross-site scripting (XSS) vulnerability in index.php in Dreamlevels DreamPoll 3.1 allows remote attackers to inject arbitrary web script or HTML via the recordsPerPage parameter in a poll_default login action.

    Source:Mark from infosecstuff
    Published:26 Mar 2010
    7.5
    High

    CVE-2009-4745

    Last Modified: 9 May 2014

    Multiple SQL injection vulnerabilities in index.php in Dreamlevels DreamPoll 3.1 allow remote attackers to execute arbitrary SQL commands via the (1) sortField, (2) sortDesc, or (3) pageNumber parameter in a login action.

    Source:infosecstuff
    Published:26 Mar 2010
    4.3
    Medium

    CVE-2009-4743

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in history-storage.aspx in AfterLogic WebMail Pro 4.7.10 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) HistoryStorageObjectName and (2) HistoryKey parameters.

    Source:Sébastien Duquette
    Published:26 Mar 2010
    7.5
    High

    CVE-2009-4742

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in Docebo 3.6.0.3 allow remote attackers to execute arbitrary SQL commands via (1) the word parameter in a play help action to the faq module, reachable through index.php; (2) the word parameter in a play keyw action to the link module, reachable through index.php; (3) the id_certificate parameter in an elemmetacertificate action to the meta_certificate module, reachable through index.php; or (4) the id_certificate parameter in an elemcertificate action to the certificate module, reachable through index.php.

    Source:Andrea Fabrizi
    Published:26 Mar 2010
    6.8
    Medium

    CVE-2009-4739

    Last Modified: 11 Apr 2025

    PHP remote file inclusion vulnerability in index.php in SkaDate Dating allows remote attackers to execute arbitrary PHP code via a URL in the language_id parameter. NOTE: this can also be leveraged to include and execute arbitrary local files via directory traversal sequences.

    Source:Moudi
    Published:26 Mar 2010
    7.5
    High

    CVE-2009-4735

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in login.php in Allomani Audio & Video Library (Songs & Clips version) 2.7.0 allows remote attackers to execute arbitrary SQL commands via the username parameter in a login action.

    Source:Qabandi
    Published:18 Mar 2010
    7.5
    High

    CVE-2009-4734

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in login.php in Allomani Movies Library (Movies & Clips) 2.7.0 allows remote attackers to execute arbitrary SQL commands via the username parameter in a login action.

    Source:Qabandi
    Published:18 Mar 2010
    6.8
    Medium

    CVE-2009-4733

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in checkuser.php in SimpleLoginSys 0.5, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: some of these details are obtained from third party information.

    Source:SirGod
    Published:18 Mar 2010
    6.8
    Medium

    CVE-2009-4732

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in tt/index.php in TT Web Site Manager 0.5, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the tt_name parameter. NOTE: some of these details are obtained from third party information.

    Source:SirGod
    Published:18 Mar 2010
    7.5
    High

    CVE-2009-4730

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in report.php in x10 Adult Media Script 1.7 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Moudi
    Published:18 Mar 2010
    4.3
    Medium

    CVE-2009-4729

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in x10 Adult Media Script 1.7 allow remote attackers to inject arbitrary web script or HTML via the (1) pic_id parameter to includes/video_ad.php, (2) category parameter to linkvideos_listing.php, (3) id parameter to templates/header1.php, and (4) key parameter to video_listing.php.

    Source:Moudi
    Published:18 Mar 2010
    7.5
    High

    CVE-2009-4728

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the administrative interface in Questions Answered 1.3 allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: some of these details are obtained from third party information.

    Source:snakespc
    Published:18 Mar 2010
    7.5
    High

    CVE-2009-4727

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in x/login in JungleScripts Ajax Short Url Script allows remote attackers to execute arbitrary SQL commands via the username parameter.

    Source:Cicklow
    Published:18 Mar 2010
    5
    Medium

    CVE-2009-4726

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in download.php in Quickdev 4 PHP allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

    Source:SirGod
    Published:18 Mar 2010
    5.1
    Medium

    CVE-2009-4725

    Last Modified: 2 Jan 2017

    Directory traversal vulnerability in modules/aljazeera/admin/setup.php in Arab Portal 2.2 and earlier, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the module parameter.

    Source:Qabandi
    Published:18 Mar 2010
    7.5
    High

    CVE-2009-4724

    Last Modified: 27 Oct 2016

    SQL injection vulnerability in shop.htm in PaymentProcessorScript.net PPScript allows remote attackers to execute arbitrary SQL commands via the cid parameter.

    Source:ZoRLu
    Published:18 Mar 2010
    7.5
    High

    CVE-2009-4723

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in confirm.php in Netpet CMS 1.9 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter.

    Source:SirGod
    Published:18 Mar 2010
    6.8
    Medium

    CVE-2009-4722

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the CheckLogin function in includes/functions.php in Limny 1.01, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the username parameter.

    Source:SirGod
    Published:18 Mar 2010
    7.5
    High

    CVE-2009-4721

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in Admin/index.asp in Andrews-Web (A-W) BannerAd 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) User and (2) Password parameters. NOTE: some of these details are obtained from third party information.

    Source:Ro0T-MaFia
    Published:18 Mar 2010