4.3
    Medium

    CVE-2009-4168

    Last Modified: 16 May 2014

    Cross-site scripting (XSS) vulnerability in Roy Tanck tagcloud.swf, as used in the WP-Cumulus plugin before 1.23 for WordPress and the Joomulus module 2.0 and earlier for Joomla!, allows remote attackers to inject arbitrary web script or HTML via the tagcloud parameter in a tags action. Cross-site scripting (XSS) vulnerability in tagcloud.swf in the WP-Cumulus Plug-in before 1.23 for WordPress allows remote attackers to inject arbitrary web script or HTML via the tagcloud parameter.

    Source:MustLive
    Published:2 Dec 2009
    4.3
    Medium

    CVE-2009-4157

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in the ProofReader (com_proofreader) component 1.0 RC9 and earlier for Joomla! allow remote attackers to inject arbitrary web script or HTML via the URI, which is not properly handled in (1) 404 or (2) error pages.

    Source:MustLive
    Published:2 Dec 2009
    7.5
    High

    CVE-2009-4156

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in modules/pms/index.php in Ciamos CMS 0.9.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the module_path parameter.

    Source:cr4wl3r
    Published:2 Dec 2009
    7.5
    High

    CVE-2009-4155

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Eshopbuilde CMS allow remote attackers to execute arbitrary SQL commands via the sitebid parameter to (1) home-f.asp and (2) opinions-f.asp; (3) sitebid, (4) id, (5) secText, (6) client-ip, and (7) G_id parameters to more-f.asp; (8) sitebid, (9) id, (10) ma_id, (11) mi_id, (12) secText, (13) client-ip, and (14) G_id parameters to selectintro.asp; (15) sitebid, (16) secText, (17) adv_code, and (18) client-ip parameters to advcount.asp; (19) sitebid, (20) secText, (21) Grp_Code, (22) _method, and (23) client-ip parameters to advview.asp; and (24) sitebid, (25) secText, (26) newsId, and (27) client-ip parameters to dis_new-f.asp.

    Source:Isfahan
    Published:2 Dec 2009
    5
    Medium

    CVE-2009-4154

    Last Modified: 16 May 2014

    Directory traversal vulnerability in includes/feedcreator.class.php in Elxis CMS allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter.

    Source:cr4wl3r
    Published:2 Dec 2009
    9.3
    Critical

    CVE-2009-4148

    Last Modified: 23 Apr 2026

    DAZ Studio 2.3.3.161, 2.3.3.163, and 3.0.1.135 allows remote attackers to execute arbitrary JavaScript code via a (1) .ds, (2) .dsa, (3) .dse, or (4) .dsb file, as demonstrated by code that loads the WScript.Shell ActiveX control, related to a "script injection vulnerability."

    Source:Core Security
    Published:4 Dec 2009
    7.2
    High

    CVE-2009-4147

    Last Modified: 4 Oct 2017

    The _rtld function in the Run-Time Link-Editor (rtld) in libexec/rtld-elf/rtld.c in FreeBSD 7.1 and 8.0 does not clear the (1) LD_LIBMAP, (2) LD_LIBRARY_PATH, (3) LD_LIBMAP_DISABLE, (4) LD_DEBUG, and (5) LD_ELF_HINTS_PATH environment variables, which allows local users to gain privileges by executing a setuid or setguid program with a modified variable containing an untrusted search path that points to a Trojan horse library, different vectors than CVE-2009-4146.

    Source:kingcope
    Published:2 Dec 2009
    7.2
    High

    CVE-2009-4146

    Last Modified: 4 Oct 2017

    The _rtld function in the Run-Time Link-Editor (rtld) in libexec/rtld-elf/rtld.c in FreeBSD 7.1, 7.2, and 8.0 does not clear the LD_PRELOAD environment variable, which allows local users to gain privileges by executing a setuid or setguid program with a modified LD_PRELOAD variable containing an untrusted search path that points to a Trojan horse library, a different vector than CVE-2009-4147.

    Source:kingcope
    Published:2 Dec 2009
    4.3
    Medium

    CVE-2009-4142

    Last Modified: 19 May 2014

    The htmlspecialchars function in PHP before 5.2.12 does not properly handle (1) overlong UTF-8 sequences, (2) invalid Shift_JIS sequences, and (3) invalid EUC-JP sequences, which allows remote attackers to conduct cross-site scripting (XSS) attacks by placing a crafted byte sequence before a special character.

    Published:6 Oct 2009
    7.2
    High

    CVE-2009-4141

    Last Modified: 27 May 2014

    Use-after-free vulnerability in the fasync_helper function in fs/fcntl.c in the Linux kernel before 2.6.33-rc4-git1 allows local users to gain privileges via vectors that include enabling O_ASYNC (aka FASYNC or FIOASYNC) on a locked file, and then closing this file.

    Source:Tavis Ormandy
    Published:16 Dec 2009
    7.5
    High

    CVE-2009-4140

    Last Modified: 26 Oct 2013

    Unrestricted file upload vulnerability in ofc_upload_image.php in Open Flash Chart v2 Beta 1 through v2 Lug Wyrm Charmer, as used in Piwik 0.2.35 through 0.4.3, Woopra Analytics Plugin before 1.4.3.2, and possibly other products, when register_globals is enabled, allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension through the name parameter with the code in the HTTP_RAW_POST_DATA parameter, then accessing it via a direct request to the file in tmp-upload-images/.

    Source:Metasploit
    Published:22 Dec 2009
    7.5
    High

    CVE-2009-4137

    Last Modified: 23 Apr 2026

    The loadContentFromCookie function in core/Cookie.php in Piwik before 0.5 does not validate strings obtained from cookies before calling the unserialize function, which allows remote attackers to execute arbitrary code or upload arbitrary files via vectors related to the __destruct function in the Piwik_Config class; php://filter URIs; the __destruct functions in Zend Framework, as demonstrated by the Zend_Log destructor; the shutdown functions in Zend Framework, as demonstrated by the Zend_Log_Writer_Mail class; the render function in the Piwik_View class; Smarty templates; and the _eval function in Smarty.

    Published:24 Dec 2009
    7.2
    High

    CVE-2009-4131

    Last Modified: 18 May 2014

    The EXT4_IOC_MOVE_EXT (aka move extents) ioctl implementation in the ext4 filesystem in the Linux kernel before 2.6.32-git6 allows local users to overwrite arbitrary files via a crafted request, related to insufficient checks for file permissions.

    Source:Akira Fujita
    Published:9 Dec 2009
    6.8
    Medium

    CVE-2009-4120

    Last Modified: 27 Oct 2016

    Multiple cross-site request forgery (CSRF) vulnerabilities in Quick.Cart 3.4 allow remote attackers to hijack the authentication of the administrator for requests that (1) delete orders via an orders-delete action to admin.php, and possibly (2) delete products or (3) delete pages via unspecified vectors.

    Source:Alice Kaerast
    Published:1 Dec 2009
    2.1
    Low

    CVE-2009-4118

    Last Modified: 9 Nov 2016

    The StartServiceCtrlDispatcher function in the cvpnd service (cvpnd.exe) in Cisco VPN client for Windows before 5.0.06.0100 does not properly handle an ERROR_FAILED_SERVICE_CONTROLLER_CONNECT error, which allows local users to cause a denial of service (service crash and VPN connection loss) via a manual start of cvpnd.exe while the cvpnd service is running.

    Source:Alex Hernandez
    Published:1 Dec 2009
    9.3
    Critical

    CVE-2009-4117

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in pdf_shade4.c in MuPDF before commit 20091125231942, as used in SumatraPDF before 1.0.1, allow remote attackers to cause a denial of service and possibly execute arbitrary code via a /Decode array for certain types of shading that are not properly handled by the (1) pdf_loadtype4shade, (2) pdf_loadtype5shade, (3) pdf_loadtype6shade, and (4) pdf_loadtype7shade functions. NOTE: some of these details are obtained from third party information.

    Source:Christophe Devine
    Published:1 Dec 2009
    6.5
    Medium

    CVE-2009-4115

    Last Modified: 23 Apr 2026

    Multiple static code injection vulnerabilities in the Categories module in CutePHP CuteNews 1.4.6 allow remote authenticated users with application administrative privileges to inject arbitrary PHP code into data/category.db.php via the (1) category and (2) Icon URL fields; or (3) inject arbitrary PHP code into data/ipban.php via the add_ip parameter.

    Source:rgod
    Published:30 Nov 2009
    4.9
    Medium

    CVE-2009-4114

    Last Modified: 23 Apr 2026

    kl1.sys in Kaspersky Anti-Virus 2010 9.0.0.463, and possibly other versions before 9.0.0.736, does not properly validate input to IOCTL 0x0022c008, which allows local users to cause a denial of service (system crash) via IOCTL requests using crafted kernel addresses that trigger memory corruption, possibly related to klavemu.kdl.

    Source:Heurs
    Published:30 Nov 2009
    9
    Critical

    CVE-2009-4112

    Last Modified: 16 May 2014

    Cacti 0.8.7e and earlier allows remote authenticated administrators to gain privileges by modifying the "Data Input Method" for the "Linux - Get Memory Usage" setting to contain arbitrary commands.

    Source:MustLive
    Published:25 Nov 2009
    4
    Medium

    CVE-2009-4108

    Last Modified: 23 Apr 2026

    XM Easy Personal FTP Server 5.8.0 allows remote authenticated users to cause a denial of service (crash) by uploading or creating a large number of files or directories, then performing a LIST command.

    Source:zhangmc
    Published:28 Nov 2009
    9.3
    Critical

    CVE-2009-4107

    Last Modified: 23 Apr 2026

    Buffer overflow in Invisible Browsing 5.0.52 allows user-assisted remote attackers to execute arbitrary code via a crafted .ibkey file containing a long string.

    Source:PLATEN
    Published:28 Nov 2009
    7.5
    High

    CVE-2009-4106

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in admintools/editpage-2.php in Agoko CMS 0.4 and earlier allows remote attackers to inject and execute arbitrary PHP code via the filename and text parameters.

    Source:StAkeR
    Published:28 Nov 2009
    3.5
    Low

    CVE-2009-4105

    Last Modified: 27 Sept 2016

    TYPSoft FTP Server 1.10 allows remote authenticated users to cause a denial of service (crash) by sending an APPE (append) command immediately followed by a DELE (delete) command without sending file data in between these two commands.

    Source:leinakesi
    Published:28 Nov 2009
    7.5
    High

    CVE-2009-4104

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Lyften Designs LyftenBloggie (com_lyftenbloggie) component 1.0.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the author parameter to index.php.

    Source:kaMtiEz
    Published:28 Nov 2009
    7.5
    High

    CVE-2009-4099

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Google Calendar GCalendar (com_gcalendar) component 1.1.2, 2.1.4, and possibly earlier versions for Joomla! allows remote attackers to execute arbitrary SQL commands via the gcid parameter. NOTE: some of these details are obtained from third party information.

    Source:Yogyacarderlink Crew
    Published:28 Nov 2009
    6
    Medium

    CVE-2009-4098

    Last Modified: 6 Mar 2011

    Unrestricted file upload vulnerability in banner-edit.php in OpenX adserver 2.8.1 and earlier allows remote authenticated users with banner / file upload permissions to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an images directory.

    Source:Metasploit
    Published:28 Nov 2009
    9.3
    Critical

    CVE-2009-4097

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the MplayInputFile function in Serenity Audio Player 3.2.3 and earlier allows remote attackers to execute arbitrary code via a long URL in an M3U file. NOTE: some of these details are obtained from third party information.

    Source:Rick2600
    Published:28 Nov 2009
    7.5
    High

    CVE-2009-4096

    Last Modified: 23 Apr 2026

    RADIO istek scripti 2.5 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain user credentials via a direct request for estafresgaftesantusyan.inc.

    Source:kurdish hackers team
    Published:28 Nov 2009
    7.5
    High

    CVE-2009-4094

    Last Modified: 6 Dec 2016

    PHP remote file inclusion vulnerability in class/php/d4m_ajax_pagenav.php in the D4J eZine (com_ezine) component 2.1 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[mosConfig_absolute_path parameter.

    Source:kaMtiEz
    Published:27 Nov 2009
    4.3
    Medium

    CVE-2009-4093

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in comments.php in Simplog 0.9.3.2, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) cname (Name) or (2) email parameters.

    Source:Amol Naik
    Published:27 Nov 2009
    6.8
    Medium

    CVE-2009-4092

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in user.php in Simplog 0.9.3.2, and possibly earlier, allows remote attackers to hijack the authentication of administrators and users for requests that change passwords.

    Source:Amol Naik
    Published:27 Nov 2009
    5
    Medium

    CVE-2009-4091

    Last Modified: 23 Apr 2026

    comments.php in Simplog 0.9.3.2, and possibly earlier, does not properly restrict access, which allows remote attackers to edit or delete comments via the (1) edit or (2) del action.

    Source:Amol Naik
    Published:27 Nov 2009
    5
    Medium

    CVE-2009-4089

    Last Modified: 23 Apr 2026

    telepark.wiki 2.4.23 and earlier allows remote attackers to bypass authorization and (1) delete arbitrary pages via a modified pageID parameter to ajax/deletePage.php or (2) delete arbitrary comments via a modified pageID parameter to ajax/deleteComment.php.

    Source:Abysssec
    Published:27 Nov 2009
    6.8
    Medium

    CVE-2009-4088

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in telepark.wiki 2.4.23 and earlier allow remote attackers to read arbitrary files via directory traversal sequences in the css parameter to (1) getjs.php and (2) getcsslocal.php; and include and execute arbitrary local files via the (3) group parameter to upload.php.

    Source:Abysssec
    Published:27 Nov 2009
    5
    Medium

    CVE-2009-4086

    Last Modified: 23 Apr 2026

    CRLF injection vulnerability in Xerver HTTP Server 4.31 and 4.32 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via certain byte sequences at the end of a URL. NOTE: some of these details are obtained from third party information.

    Source:s4squatch
    Published:27 Nov 2009
    7.5
    High

    CVE-2009-4085

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in assets/plugins/mp3_id/mp3_id.php in PHP Traverser 0.8.0 allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[BASE] parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:cr4wl3r
    Published:27 Nov 2009
    7.5
    High

    CVE-2009-4082

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in forums/Forum_Include/index.php in Outreach Project Tool (OPT) 1.2.7 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the CRM_path parameter.

    Source:cr4wl3r
    Published:27 Nov 2009
    6.8
    Medium

    CVE-2009-4067

    Last Modified: 30 Jan 2015

    Buffer overflow in the auerswald_probe function in the Auerswald Linux USB driver for the Linux kernel before 2.6.27 allows physically proximate attackers to execute arbitrary code, cause a denial of service via a crafted USB device, or take full control of the system.

    Source:R. Dominguez Veg
    Published:29 Oct 2009
    7.5
    High

    CVE-2009-4060

    Last Modified: 15 May 2014

    SQL injection vulnerability in includes/content/viewProd.inc.php in CubeCart before 4.3.7 remote attackers to execute arbitrary SQL commands via the productId parameter.

    Source:Sangte Amtham
    Published:24 Nov 2009
    6.8
    Medium

    CVE-2009-4059

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the JoomClip (com_joomclip) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cat parameter in a thumbs action to index.php.

    Source:599eme Man
    Published:24 Nov 2009
    7.5
    High

    CVE-2009-4058

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in allauctions.php in Telebid Auction Script allows remote attackers to execute arbitrary SQL commands via the aid parameter.

    Source:Hussin X
    Published:24 Nov 2009
    7.5
    High

    CVE-2009-4057

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the inertialFATE iF Portfolio Nexus (com_if_nexus) component 1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in an item action to index.php.

    Source:599eme Man
    Published:24 Nov 2009
    7.5
    High

    CVE-2009-4056

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in admin/popup.php in Betsy CMS 3.5 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the popup parameter.

    Source:MizoZ
    Published:24 Nov 2009
    6.5
    Medium

    CVE-2009-4053

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in Home FTP Server 1.10.1.139 allow remote authenticated users to (1) create arbitrary directories via directory traversal sequences in an MKD command or (2) create files with any contents in arbitrary directories via directory traversal sequences in a file upload request. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:zhangmc
    Published:23 Nov 2009
    5
    Medium

    CVE-2009-4051

    Last Modified: 23 Apr 2026

    Home FTP Server 1.10.1.139 allows remote attackers to cause a denial of service (daemon outage) via multiple invalid SITE INDEX commands.

    Source:zhangmc
    Published:23 Nov 2009
    5
    Medium

    CVE-2009-4050

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in get_file.php in phpMyBackupPro 2.1 allows remote attackers to read arbitrary files via directory traversal sequences in the view parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Amol Naik
    Published:23 Nov 2009
    7.2
    High

    CVE-2009-4049

    Last Modified: 15 May 2014

    Heap-based buffer overflow in aswRdr.sys (aka the TDI RDR driver) in avast! Home and Professional 4.8.1356.0 allows local users to cause a denial of service (memory corruption) or possibly gain privileges via crafted arguments to IOCTL 0x80002024.

    Source:Evilcry
    Published:23 Nov 2009
    4
    Medium

    CVE-2009-4048

    Last Modified: 23 Apr 2026

    Dxmsoft XM Easy Personal FTP Server 5.8.0 allows remote authenticated users to cause a denial of service (daemon outage) via an APPE command to one socket in conjunction with a DELE command to a second socket.

    Source:zhangmc
    Published:23 Nov 2009
    4.3
    Medium

    CVE-2009-4047

    Last Modified: 15 May 2014

    Multiple cross-site scripting (XSS) vulnerabilities in PHD Help Desk 1.43 allow remote attackers to inject arbitrary web script or HTML via (1) the PATH_INFO to area.php; the (2) pagina, (3) sentido, (4) q_registros, and (5) orden parameters to area.php; (6) the q_registros parameter to solic_display.php; (7) the PATH_INFO to area_list.php; (8) the q_registros parameter to area_list.php; (9) the PATH_INFO to atributo.php; the (10) pagina, (11) q_registros, and (12) orden parameters to atributo_list.php; (13) an arbitrary parameter name beginning with "sentido" to atributo_list.php; and (14) the PATH_INFO to caso_insert.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Amol Naik
    Published:23 Nov 2009
    4.3
    Medium

    CVE-2009-4039

    Last Modified: 19 Aug 2014

    Cross-site scripting (XSS) vulnerability in Piwigo before 2.0.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Source:Andrew Paterson
    Published:20 Nov 2009