7.5
    High

    CVE-2009-4465

    Last Modified: 25 Nov 2016

    DeluxeBB 1.3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain user and configuration information, log data, and gain administrative access via a direct request to scripts in (1) templates/ including (2) templates/deluxe/admincp/, (3) templates/corporate/admincp/, and (4) templates/blue/admincp/; (5) images/; (6) logs/ including (7) logs/cp.php; (8) wysiwyg/; (9) docs/; (10) classes/; (11) lang/; and (12) settings/.

    Source:cp77fk4r
    Published:30 Dec 2009
    4.3
    Medium

    CVE-2009-4464

    Last Modified: 20 Aug 2014

    Cross-site scripting (XSS) vulnerability in searchadvance.asp in Active Business Directory 2 allows remote attackers to inject arbitrary web script or HTML via the search parameter.

    Source:Andrea Bocchetti
    Published:30 Dec 2009
    10
    Critical

    CVE-2009-4462

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the NetBiterConfig utility (NetBiterConfig.exe) 1.3.0 for Intellicom NetBiter WebSCADA allows remote attackers to execute arbitrary code via a long hn (hostname) parameter in a crafted HICP-protocol UDP packet.

    Source:Ruben Santamarta
    Published:30 Dec 2009
    4.3
    Medium

    CVE-2009-4461

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in FlatPress 0.909 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) contact.php, (2) login.php, and (3) search.php.

    Source:indoushka
    Published:30 Dec 2009
    4.3
    Medium

    CVE-2009-4458

    Last Modified: 20 May 2014

    Multiple cross-site scripting (XSS) vulnerabilities in FreePBX 2.5.2 and 2.6.0rc2, and possibly other versions, allow remote attackers to inject arbitrary web script or HTML via the (1) tech parameter to admin/admin/config.php during a trunks display action, the (2) description parameter during an Add Zap Channel action, and (3) unspecified vectors during an Add Recordings action.

    Source:Global-Evolution
    Published:30 Dec 2009
    7.5
    High

    CVE-2009-4456

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in news_detail.php in Green Desktiny 2.3.1, and possibly earlier versions, allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:kaMtiEz
    Published:30 Dec 2009
    3.3
    Low

    CVE-2009-4454

    Last Modified: 21 Sept 2016

    vccleaner in VideoCache 1.9.2 allows local users with Squid proxy user privileges to overwrite arbitrary files via a symlink attack on /var/log/videocache/vccleaner.log.

    Source:Dominick LaTrappe
    Published:29 Dec 2009
    8.8
    High

    CVE-2009-4453

    Last Modified: 23 Apr 2026

    Insecure method vulnerability in SoftCab Sound Converter ActiveX control (sndConverter.ocx) 1.2 allows remote attackers to create or overwrite arbitrary files via the SaveFormat method. NOTE: some of these details are obtained from third party information.

    Source:ThE g0bL!N
    Published:29 Dec 2009
    6.8
    Medium

    CVE-2009-4452

    Last Modified: 23 Apr 2026

    Kaspersky Anti-Virus 5.0 (5.0.712); Antivirus Personal 5.0.x; Anti-Virus 6.0 (6.0.3.837), 7 (7.0.1.325), 2009 (8.0.0.x), and 2010 (9.0.0.463); and Internet Security 7 (7.0.1.325), 2009 (8.0.0.x), and 2010 (9.0.0.463); use weak permissions (Everyone:Full Control) for the BASES directory, which allows local users to gain SYSTEM privileges by replacing an executable or DLL with a Trojan horse.

    Source:Maxim A. Kulakov
    Published:29 Dec 2009
    6.8
    Medium

    CVE-2009-4451

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in upper.php in kandalf upper 0.1 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in fileup/.

    Source:indoushka
    Published:29 Dec 2009
    4.3
    Medium

    CVE-2009-4450

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in map.php in LiveZilla 3.1.8.3 allow remote attackers to inject arbitrary web script or HTML via the (1) lat, (2) lng, and (3) zom parameters, which are not properly handled when processed with templates/map.tpl.

    Source:MaXe
    Published:29 Dec 2009
    7.5
    High

    CVE-2009-4447

    Last Modified: 23 Apr 2026

    Jax Guestbook 3.5.0 allows remote attackers to bypass authentication and modify administrator settings via a direct request to admin/guestbook.admin.php.

    Source:Sora
    Published:29 Dec 2009
    4.3
    Medium

    CVE-2009-4446

    Last Modified: 20 May 2014

    Cross-site scripting (XSS) vulnerability in admin.php in phpInstantGallery 1.1 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.

    Source:indoushka
    Published:29 Dec 2009
    7.5
    High

    CVE-2009-4437

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Active Auction House 3.6 allow remote attackers to execute arbitrary SQL commands via the (1) catid parameter to wishlist.asp and the (2) linkid parameter to links.asp. NOTE: vector 1 might overlap CVE-2005-1029.1.

    Source:R3d-D3V!L
    Published:28 Dec 2009
    7.5
    High

    CVE-2009-4436

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Active Web Softwares eWebquiz 8 allow remote attackers to execute arbitrary SQL commands via the QuizID parameter to (1) questions.asp, (2) importquestions.asp, and (3) quiztakers.asp, different vectors than CVE-2007-1706.

    Source:R3d-D3V!L
    Published:28 Dec 2009
    6.8
    Medium

    CVE-2009-4435

    Last Modified: 19 May 2014

    Multiple directory traversal vulnerabilities in F3Site 2009 allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the GLOBALS[nlang] parameter to (1) mod/poll.php and (2) mod/new.php.

    Source:cr4wl3r
    Published:28 Dec 2009
    5
    Medium

    CVE-2009-4434

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in IDevSpot iSupport 1.8 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the include_file parameter.

    Source:Stink & Essandre
    Published:28 Dec 2009
    4.3
    Medium

    CVE-2009-4433

    Last Modified: 19 May 2014

    Multiple cross-site scripting (XSS) vulnerabilities in IDevSpot iSupport 1.8 and earlier allow remote attackers to inject arbitrary web script or HTML via the (a) 5 or (b) 9 field in a post action to ticket_function.php, reachable through ticket_submit.php and index.php; (c) the which parameter to function.php, or (d) the which parameter to index.php, related to knowledgebase_list.php. NOTE: some of these details are obtained from third party information.

    Source:Stink & Essandre
    Published:28 Dec 2009
    7.5
    High

    CVE-2009-4432

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in CodeMight VideoCMS 3.1 allows remote attackers to execute arbitrary SQL commands via the v parameter in a video action.

    Source:kaMtiEz
    Published:28 Dec 2009
    7.5
    High

    CVE-2009-4431

    Last Modified: 12 Jul 2015

    PHP remote file inclusion vulnerability in cal_popup.php in the Anything Digital Development JCal Pro (aka com_jcalpro or JCP) component 1.5.3.6 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Source:kaMtiEz
    Published:28 Dec 2009
    7.5
    High

    CVE-2009-4430

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in VirtueMart 1.0 allows remote attackers to execute arbitrary SQL commands via the product_id parameter in a shop.product_details shop.flypage action.

    Source:Neo-GabrieL
    Published:28 Dec 2009
    3.5
    Low

    CVE-2009-4429

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Sections module 5.x before 5.x-1.3 and 6.x before 6.x-1.3 for Drupal allows remote authenticated users with "administer sections" privileges to inject arbitrary web script or HTML via a section name (aka the Name field).

    Source:Justin C. Klein Keane
    Published:28 Dec 2009
    7.5
    High

    CVE-2009-4428

    Last Modified: 19 May 2014

    SQL injection vulnerability in the JoomPortfolio (com_joomportfolio) component 1.0.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the secid parameter in a showcat action to index.php.

    Source:Fl0riX & Snakespc
    Published:28 Dec 2009
    7.5
    High

    CVE-2009-4427

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in cmd.php in phpLDAPadmin 1.1.0.5 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the cmd parameter.

    Source:ipsecs
    Published:10 Dec 2009
    6.8
    Medium

    CVE-2009-4426

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in Ignition 1.2, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the blog parameter to (1) comment.php and (2) view.php.

    Source:cOndemned
    Published:28 Dec 2009
    7.5
    High

    CVE-2009-4424

    Last Modified: 12 Jul 2015

    SQL injection vulnerability in results.php in the Pyrmont plugin 2 for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Gamoscu
    Published:28 Dec 2009
    7.5
    High

    CVE-2009-4423

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in weenCompany 4.0.0 allows remote attackers to execute arbitrary SQL commands via the moduleid parameter. NOTE: some of these details are obtained from third party information.

    Source:Gamoscu
    Published:24 Dec 2009
    6.5
    Medium

    CVE-2009-4421

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in languages_cgi.php in Simple PHP Blog 0.5.1 and earlier allows remote authenticated users to include and execute arbitrary local files via a .. (dot dot) in the blog_language1 parameter.

    Source:jgaliana
    Published:24 Dec 2009
    5
    Medium

    CVE-2009-4413

    Last Modified: 23 Apr 2026

    The httpClientDiscardBody function in client.c in Polipo 0.9.8, 0.9.12, 1.0.4, and possibly other versions, allows remote attackers to cause a denial of service (crash) via a request with a large Content-Length value, which triggers an integer overflow, a signed-to-unsigned conversion error with a negative value, and a segmentation fault.

    Source:Jeremy Brown
    Published:24 Dec 2009
    4.3
    Medium

    CVE-2009-4403

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Rumba XML 1.8 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO. NOTE: some of these details are obtained from third party information.

    Source:Hadi Kiamarsi
    Published:23 Dec 2009
    7.5
    High

    CVE-2009-4386

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in hotel_tiempolibre_ext.php in Venalsur Booking Centre Booking System for Hotels Group, when magic_quotes_gpc is enabled, allows remote attackers to execute arbitrary SQL commands via the NoticiaID parameter and other unspecified vectors.

    Source:Salvatore Fresta
    Published:22 Dec 2009
    6.8
    Medium

    CVE-2009-4385

    Last Modified: 23 Apr 2026

    Multiple cross-site request forgery (CSRF) vulnerabilities in Scriptsez.net Ez Poll Hoster (EPH) allow remote attackers to (1) hijack the authentication of arbitrary users for requests that delete polls via the delete_poll action to index.php; and hijack the authentication of administrators for requests that (2) delete users via the manage action to admin.php, or (3) send arbitrary email to arbitrary users in the email action to admin.php.

    Source:Milos Zivanovic
    Published:22 Dec 2009
    4.3
    Medium

    CVE-2009-4384

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Scriptsez.net Ez Poll Hoster (EPH) allow remote attackers to inject arbitrary web script or HTML via the (1) pid parameter in a code action to index.php and the (2) uid parameter in a view action to profile.php.

    Source:Milos Zivanovic
    Published:22 Dec 2009
    4.3
    Medium

    CVE-2009-4382

    Last Modified: 18 May 2014

    Cross-site scripting (XSS) vulnerability in module.php in PHPFABER CMS, possibly 1.3.36, allows remote attackers to inject arbitrary web script or HTML via the mod parameter.

    Source:bi0
    Published:22 Dec 2009
    4.3
    Medium

    CVE-2009-4381

    Last Modified: 18 May 2014

    Cross-site scripting (XSS) vulnerability in index.php in texmedia Million Pixel Script 3 allows remote attackers to inject arbitrary web script or HTML via the pa parameter. NOTE: some of these details are obtained from third party information.

    Source:bi0
    Published:22 Dec 2009
    7.5
    High

    CVE-2009-4375

    Last Modified: 9 Jul 2010

    SQL injection vulnerability in repository/repository_attachment.php in AlienVault Open Source Security Information Management (OSSIM) 2.1.5, and possibly other versions before 2.1.5-4, allows remote attackers to execute arbitrary SQL commands via the id_document parameter.

    Source:Nahuel Grisolia
    Published:21 Dec 2009
    7.5
    High

    CVE-2009-4372

    Last Modified: 12 Jul 2015

    AlienVault Open Source Security Information Management (OSSIM) 2.1.5, and possibly other versions before 2.1.5-4, allows remote attackers to execute arbitrary commands via shell metacharacters in the uniqueid parameter to (1) wcl.php, (2) storage_graphs.php, (3) storage_graphs2.php, (4) storage_graphs3.php, and (5) storage_graphs4.php in sem/.

    Source:Nahuel Grisolia
    Published:21 Dec 2009
    6.8
    Medium

    CVE-2009-4367

    Last Modified: 23 Apr 2026

    The Staging Webservice ("sitecore modules/staging/service/api.asmx") in Sitecore Staging Module 5.4.0 rev.080625 and earlier allows remote attackers to bypass authentication and (1) upload files, (2) download files, (3) list directories, and (4) clear the server cache via crafted SOAP requests with arbitrary Username and Password values, possibly related to a direct request.

    Source:L. Weichselbaum
    Published:21 Dec 2009
    4.3
    Medium

    CVE-2009-4366

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in ScriptsEz Ez Blog 1.0 allows remote attackers to inject arbitrary web script or HTML via the yr parameter in a bmonth action.

    Source:Milos Zivanovic
    Published:21 Dec 2009
    4.3
    Medium

    CVE-2009-4365

    Last Modified: 23 Apr 2026

    Multiple cross-site request forgery (CSRF) vulnerabilities in admin.php in ScriptsEz Ez Blog 1.0 allow remote attackers to hijack the authentication of administrators for requests that (1) add a blog via the add_blog action, (2) approve a comment via the approve_comment action, (3) change administrator information including the password via the admin_opt action, and (4) delete a blog via the delete action.

    Source:Milos Zivanovic
    Published:21 Dec 2009
    4.3
    Medium

    CVE-2009-4364

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in ScriptsEz Ez Blog allows remote attackers to inject arbitrary web script or HTML via the cname parameter, related to the act and id parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Milos Zivanovic
    Published:21 Dec 2009
    7.5
    High

    CVE-2009-4360

    Last Modified: 16 May 2014

    SQL injection vulnerability in modules/content/index.php in the Content module 0.5 for XOOPS allows remote attackers to inject arbitrary web script or HTML via the id parameter.

    Source:s4r4d0
    Published:20 Dec 2009
    4.3
    Medium

    CVE-2009-4359

    Last Modified: 16 May 2014

    Cross-site scripting (XSS) vulnerability in folder.php in the SmartMedia 0.85 Beta module for XOOPS allows remote attackers to inject arbitrary web script or HTML via the categoryid parameter.

    Source:SoldierOfAllah
    Published:20 Dec 2009
    6.8
    Medium

    CVE-2009-4351

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in ADMIN/loginaction.php in WSCreator 1.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the Email (aka username) parameter.

    Source:Salvatore Fresta
    Published:17 Dec 2009
    6.8
    Medium

    CVE-2009-4349

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in administration/administrators.php in Link Up Gold 5.0 allows remote attackers to hijack the authentication of administrators for requests that create administrative accounts.

    Source:bi0
    Published:17 Dec 2009
    7.8
    High

    CVE-2009-4324

    Last Modified: 10 Mar 2011

    Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code via a crafted PDF file using ZLib compressed streams, as exploited in the wild in December 2009.

    Source:Metasploit
    Published:14 Dec 2009
    6.8
    Medium

    CVE-2009-4319

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in js/bbcodepress/bbcode-form.php in eoCMS 0.9.03 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the BBCODE_path parameter.

    Source:1nd0n3s14n l4m3r
    Published:14 Dec 2009
    6.8
    Medium

    CVE-2009-4315

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in admin/ajaxsave.php in Nuggetz CMS 1.0, when magic_quotes_gpc is disabled, allows remote attackers to create or modify arbitrary files via a .. (dot dot) in the nugget parameter and a modified pagevalue parameter, as demonstrated by creating and accessing a .php file to execute arbitrary PHP code.

    Source:Amol Naik
    Published:14 Dec 2009
    10
    Critical

    CVE-2009-4273

    Last Modified: 27 May 2014

    stap-server in SystemTap before 1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in stap command-line arguments in a request.

    Source:Frank Ch. Eigler
    Published:18 Dec 2009
    4.3
    Medium

    CVE-2009-4266

    Last Modified: 28 Jun 2011

    Cross-site scripting (XSS) vulnerability in search.php in YABSoft Advanced Image Hosting (AIH) Script 2.2, and possibly 2.3, allows remote attackers to inject arbitrary web script or HTML via the text parameter.

    Source:R3VAN_BASTARD
    Published:10 Dec 2009