7.8
    High

    CVE-2009-3489

    Last Modified: 23 Apr 2026

    Adobe Photoshop Elements 8.0 installs the Adobe Active File Monitor V8 service with an insecure security descriptor, which allows local users to (1) stop the service via the stop command, (2) execute arbitrary commands as SYSTEM by using the config command to modify the binPath variable, or (3) restart the service via the start command.

    Source:bellick
    Published:30 Sept 2009
    3.5
    Low

    CVE-2009-3487

    Last Modified: 9 May 2014

    Multiple cross-site scripting (XSS) vulnerabilities in the J-Web interface in Juniper JUNOS 8.5R1.14 allow remote authenticated users to inject arbitrary web script or HTML via (1) the JEXEC_OUTID parameter in a JEXEC_MODE_RELAY_OUTPUT action to the jexec program; the (2) act, (3) refresh-time, or (4) ifid parameter to scripter.php; (5) the revision parameter in a rollback action to the configuration program; the m[] parameter to the (6) monitor, (7) manage, (8) events, (9) configuration, or (10) alarms program; (11) the m[] parameter to the default URI; (12) the m[] parameter in a browse action to the default URI; (13) the wizard-next parameter in an https action to the configuration program; or the (14) Contact Information, (15) System Description, (16) Local Engine ID, (17) System Location, or (18) System Name Override SNMP parameter, related to the configuration program.

    Source:Amir Azam
    Published:30 Sept 2009
    3.5
    Low

    CVE-2009-3486

    Last Modified: 9 May 2014

    Multiple cross-site scripting (XSS) vulnerabilities in the J-Web interface in Juniper JUNOS 8.5R1.14 allow remote authenticated users to inject arbitrary web script or HTML via the host parameter to (1) the pinghost program, reachable through the diagnose program; or (2) the traceroute program, reachable through the diagnose program; or (3) the probe-limit parameter to the configuration program; the (4) wizard-ids or (5) pager-new-identifier parameter in a firewall-filters action to the configuration program; (6) the cos-physical-interface-name parameter in a cos-physical-interfaces-edit action to the configuration program; the (7) wizard-args or (8) wizard-ids parameter in an snmp action to the configuration program; the (9) username or (10) fullname parameter in a users action to the configuration program; or the (11) certname or (12) certbody parameter in a local-cert (aka https) action to the configuration program.

    Source:Amir Azam
    Published:30 Sept 2009
    4.3
    Medium

    CVE-2009-3485

    Last Modified: 9 May 2014

    Cross-site scripting (XSS) vulnerability in the J-Web interface in Juniper JUNOS 8.5R1.14 and 9.0R1.1 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default URI.

    Source:Amir Azam
    Published:30 Sept 2009
    9.3
    Critical

    CVE-2009-3484

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Core FTP 2.1 build 1612 allows user-assisted remote attackers to execute arbitrary code via a long hostname in an FTP server entry in a site backup file. NOTE: some of these details are obtained from third party information.

    Source:Dr_IDE
    Published:30 Sept 2009
    4.3
    Medium

    CVE-2009-3469

    Last Modified: 9 May 2014

    Cross-site scripting (XSS) vulnerability in profiles/html/simpleSearch.do in IBM Lotus Connections 2.0.1 allows remote attackers to inject arbitrary web script or HTML via the name parameter.

    Source:IBM
    Published:29 Sept 2009
    8.8
    High

    CVE-2009-3459

    Last Modified: 10 Mar 2011

    Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption, as exploited in the wild in October 2009. NOTE: some of these details are obtained from third party information.

    Source:Metasploit
    Published:8 Oct 2009
    5
    Medium

    CVE-2009-3457

    Last Modified: 23 Apr 2026

    Cisco ACE XML Gateway (AXG) and ACE Web Application Firewall (WAF) before 6.1 allow remote attackers to obtain sensitive information via an HTTP request that lacks a handler, as demonstrated by (1) an OPTIONS request or (2) a crafted GET request, leading to a Message-handling Errors message containing a certain client intranet IP address, aka Bug ID CSCtb82159.

    Source:nitr0us
    Published:29 Sept 2009
    4.3
    Medium

    CVE-2009-3449

    Last Modified: 23 Apr 2026

    MP3 Collector 2.3 allows remote attackers to cause a denial of service (application crash) via a long URL in a .m3u playlist file.

    Source:zAx
    Published:29 Sept 2009
    7.5
    High

    CVE-2009-3446

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the MyRemote Video Gallery (com_mytube) component 1.0 Beta for Joomla! allows remote attackers to execute arbitrary SQL commands via the user_id parameter in a videos action to index.php.

    Source:Chip d3 bi0s
    Published:28 Sept 2009
    4.3
    Medium

    CVE-2009-3444

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in email.php in e107 0.7.16 and earlier allows remote attackers to inject arbitrary web script or HTML via the HTTP Referer header in a news.1 (aka news to email) action.

    Source:MustLive
    Published:28 Sept 2009
    7.5
    High

    CVE-2009-3443

    Last Modified: 16 Feb 2018

    SQL injection vulnerability in the Fastball (com_fastball) component 1.1.0 through 1.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the league parameter to index.php.

    Source:kaMtiEz
    Published:28 Sept 2009
    4.3
    Medium

    CVE-2009-3440

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Open Source Security Information Management (OSSIM) before 2.1.2 allows remote attackers to inject arbitrary web script or HTML via the option parameter to the default URI (aka the main menu).

    Source:Alexey Sintsov
    Published:28 Sept 2009
    6.5
    Medium

    CVE-2009-3439

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Open Source Security Information Management (OSSIM) before 2.1.2 allow remote authenticated users to execute arbitrary SQL commands via the id_document parameter to (1) repository_document.php, (2) repository_links.php, and (3) repository_editdocument.php in repository/; the (4) group parameter to policy/getpolicy.php; the name parameter to (5) host/newhostgroupform.php and (6) net/modifynetform.php; and unspecified other vectors related to the policy menu.

    Source:Alexey Sintsov
    Published:28 Sept 2009
    7.5
    High

    CVE-2009-3438

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the JoomlaFacebook (com_facebook) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a student action to index.php.

    Source:kaMtiEz
    Published:28 Sept 2009
    7.5
    High

    CVE-2009-3436

    Last Modified: 8 May 2014

    Multiple SQL injection vulnerabilities in forum.asp in MaxWebPortal allow remote attackers to execute arbitrary SQL commands via the (1) FORUM_ID or (2) CAT_ID parameter. NOTE: this might overlap CVE-2005-1417.

    Source:OoN_Boy
    Published:28 Sept 2009
    7.5
    High

    CVE-2009-3434

    Last Modified: 6 Dec 2016

    SQL injection vulnerability in the Tupinambis (com_tupinambis) component 1.0 for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the proyecto parameter in a verproyecto action to index.php.

    Source:Don Tukulesto
    Published:28 Sept 2009
    5
    Medium

    CVE-2009-3431

    Last Modified: 26 Apr 2014

    Stack consumption vulnerability in Adobe Reader and Acrobat 9.1.3, 9.1.2, 9.1.1, and earlier 9.x versions; 8.1.6 and earlier 8.x versions; and possibly 7.1.4 and earlier 7.x versions allows remote attackers to cause a denial of service (application crash) via a PDF file with a large number of [ (open square bracket) characters in the argument to the alert method. NOTE: some of these details are obtained from third party information.

    Source:Saint Patrick
    Published:25 Sept 2009
    7.5
    High

    CVE-2009-3430

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in login.php in Allomani Mobile 2.5 allows remote attackers to execute arbitrary SQL commands via the username parameter in a login action.

    Source:Qabandi
    Published:25 Sept 2009
    9.3
    Critical

    CVE-2009-3429

    Last Modified: 7 Jan 2011

    Stack-based buffer overflow in Pirate Radio Destiny Media Player 1.61 allows remote attackers to execute arbitrary code via a long string in a .pls playlist file.

    Source:Encrypt3d.M!nd
    Published:25 Sept 2009
    9.3
    Critical

    CVE-2009-3428

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Easy Music Player 1.0.0.2 allows remote attackers to execute arbitrary code via a crafted .wav file.

    Source:ahwak2000
    Published:25 Sept 2009
    6.8
    Medium

    CVE-2009-3426

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in includes/file_manager/special.php in MaxCMS 3.11.20b allows remote attackers to execute arbitrary PHP code via a URL in the fm_includes_special parameter.

    Source:GoLd_M
    Published:25 Sept 2009
    5
    Medium

    CVE-2009-3425

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in includes/inc.thcms_admin_dirtree.php in MaxCMS 3.11.20b allows remote attackers to read arbitrary files via directory traversal sequences in the thCMS_root parameter.

    Source:GoLd_M
    Published:25 Sept 2009
    6.8
    Medium

    CVE-2009-3424

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in MaxCMS 3.11.20b, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) is_projectPath parameter to includes/InstantSite/inc.is_root.php; GLOBALS[thCMS_root] parameter to (2) classes/class.Tree.php, (3) includes/inc.thcms_admin_mediamanager.php, and (4) modul/mod.rssreader.php; is_path parameter to (5) class.tasklist.php, (6) class.thcms.php, (7) class.thcms_content.php, (8) class.thcms_modul_parent.php, (9) class.thcms_page.php, and (10) class.thcsm_user.php in classes/; and (11) includes/InstantSite/class.Tree.php; and thCMS_root parameter to (12) classes/class.thcms_modul.php; (13) inc.page_edit_tasklist.php, (14) inc.thcms_admin_overview_backup.php, and (15) inc.thcms_edit_content.php in includes/; and (16) class.thcms_modul_parent_xml.php, (17) mod.cmstranslator.php, (18) mod.download.php, (19) mod.faq.php, (20) mod.guestbook.php, (21) mod.html.php, (22) mod.menu.php, (23) mod.news.php, (24) mod.newsticker.php, (25) mod.rss.php, (26) mod.search.php, (27) mod.sendtofriend.php, (28) mod.sitemap.php, (29) mod.tagdoc.php, (30) mod.template.php, (31) mod.test.php, (32) mod.text.php, (33) mod.upload.php, and (34) mod.users.php in modul/.

    Source:NoGe
    Published:25 Sept 2009
    6.8
    Medium

    CVE-2009-3423

    Last Modified: 23 Apr 2026

    login.php in Zenas PaoLink 1.0, when register_globals is enabled, allows remote attackers to bypass authentication and gain administrative access by setting the login_ok parameter to 1.

    Source:SirGod
    Published:25 Sept 2009
    6.8
    Medium

    CVE-2009-3422

    Last Modified: 23 Apr 2026

    login.php in Zenas PaoLiber 1.1, when register_globals is enabled, allows remote attackers to bypass authentication and gain administrative access by setting the login_ok parameter to 1.

    Source:SirGod
    Published:25 Sept 2009
    9.8
    Critical

    CVE-2009-3421

    Last Modified: 23 Apr 2026

    login.php in Zenas PaoBacheca Guestbook 2.1, when register_globals is enabled, allows remote attackers to bypass authentication and gain administrative access by setting the login_ok parameter to 1.

    Source:SirGod
    Published:25 Sept 2009
    4.3
    Medium

    CVE-2009-3420

    Last Modified: 26 Oct 2016

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in the Publisher module 2.0 for Miniweb allow remote attackers to inject arbitrary web script or HTML via the (1) begin parameter and the (2) PATH_INFO.

    Source:Moudi
    Published:25 Sept 2009
    7.5
    High

    CVE-2009-3419

    Last Modified: 26 Oct 2016

    SQL injection vulnerability in index.php in the Publisher module 2.0 for Miniweb allows remote attackers to execute arbitrary SQL commands via the historymonth parameter.

    Source:Moudi
    Published:25 Sept 2009
    6.5
    Medium

    CVE-2009-3418

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Plume CMS 1.2.3 allow (1) remote authenticated users to execute arbitrary SQL commands via the m parameter to manager/index.php and (2) remote authenticated administrators to execute arbitrary SQL commands via the id parameter in an edit_link action to manager/tools.php. NOTE: some of these details are obtained from third party information.

    Source:Sense of Security
    Published:25 Sept 2009
    7.5
    High

    CVE-2009-3417

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the IDoBlog (com_idoblog) component 1.1 build 30 for Joomla! allows remote attackers to execute arbitrary SQL commands via the userid parameter in a profile action to index.php, a different vector than CVE-2008-2627.

    Source:kkr
    Published:25 Sept 2009
    10
    Critical

    CVE-2009-3382

    Last Modified: 12 May 2014

    layout/base/nsCSSFrameConstructor.cpp in the browser engine in Mozilla Firefox 3.0.x before 3.0.15 does not properly handle first-letter frames, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors.

    Source:Carsten Book
    Published:27 Oct 2009
    10
    Critical

    CVE-2009-3373

    Last Modified: 27 Oct 2017

    Heap-based buffer overflow in the GIF image parser in Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, allows remote attackers to execute arbitrary code via unspecified vectors.

    Source:regenrecht
    Published:27 Oct 2009
    4.3
    Medium

    CVE-2009-3368

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Hotel Booking Reservation System (aka HBS or com_hbssearch) component for Joomla! allows remote attackers to inject arbitrary web script or HTML via the adult parameter in a showhoteldetails action to index.php.

    Source:K-159
    Published:24 Sept 2009
    4.3
    Medium

    CVE-2009-3367

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in An image gallery 1.0 allow remote attackers to inject arbitrary web script or HTML via the path parameter to (1) index.php and (2) main.php, and the (3) show parameter to main.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:ThE g0bL!N
    Published:24 Sept 2009
    5
    Medium

    CVE-2009-3366

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in navigation.php in An image gallery 1.0 allows remote attackers to list arbitrary directories via a .. (dot dot) in the path parameter.

    Source:ThE g0bL!N
    Published:24 Sept 2009
    7.5
    High

    CVE-2009-3365

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in add-ons/modules/sysmanager/plugins/install.plugin.php in Aurora CMS 1.0.2 allows remote attackers to execute arbitrary PHP code via a URL in the AURORA_MODULES_FOLDER parameter.

    Source:EA Ngel
    Published:24 Sept 2009
    9.3
    Critical

    CVE-2009-3364

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in FTPShell Client 4.1 RC2 allows remote FTP servers to execute arbitrary code via a long response to a PASV command.

    Source:His0k4
    Published:24 Sept 2009
    7.5
    High

    CVE-2009-3362

    Last Modified: 9 Sept 2014

    PHP remote file inclusion vulnerability in printnews.php3 in SZNews 2.7 allows remote attackers to execute arbitrary PHP code via a URL in the id parameter.

    Source:kurdish hackers team
    Published:24 Sept 2009
    7.5
    High

    CVE-2009-3361

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in PHP-IPNMonitor allows remote attackers to execute arbitrary SQL commands via the maincat_id parameter.

    Source:noname
    Published:24 Sept 2009
    4.3
    Medium

    CVE-2009-3360

    Last Modified: 7 Sept 2014

    Multiple cross-site scripting (XSS) vulnerabilities in Datemill 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) return parameter to photo_view.php, and st parameter to (2) photo_search.php and (3) search.php.

    Source:Moudi
    Published:24 Sept 2009
    4.3
    Medium

    CVE-2009-3359

    Last Modified: 9 Sept 2014

    Multiple cross-site scripting (XSS) vulnerabilities in Match Agency BiZ 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) important parameter to edit_profile.php and (2) pid parameter to report.php.

    Source:Moudi
    Published:24 Sept 2009
    7.5
    High

    CVE-2009-3358

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in profile.php in Tourism Scripts Adult Portal escort listing allows remote attackers to execute arbitrary SQL commands via the user_id parameter.

    Source:Mr.SQL
    Published:24 Sept 2009
    7.5
    High

    CVE-2009-3357

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in the Hotel Booking Reservation System (aka HBS or com_hbssearch) component for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) h_id, (2) id, and (3) rid parameters to longDesc.php, and the h_id parameter to (4) detail.php, (5) detail1.php, (6) detail2.php, (7) detail3.php, (8) detail4.php, (9) detail5.php, (10) detail6.php, (11) detail7.php, and (12) detail8.php, different vectors than CVE-2008-5865, CVE-2008-5874, and CVE-2008-5875.

    Source:K-159
    Published:24 Sept 2009
    7.5
    High

    CVE-2009-3356

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Image voting 1.0 allows remote attackers to execute arbitrary SQL commands via the show parameter.

    Source:SkuLL-HackeR
    Published:24 Sept 2009
    4.3
    Medium

    CVE-2009-3355

    Last Modified: 9 Sept 2014

    Cross-site scripting (XSS) vulnerability in profile.php in Datetopia Buy Dating Site 1.0 allows remote attackers to inject arbitrary web script or HTML via the s_r parameter.

    Source:Moudi
    Published:24 Sept 2009
    7.5
    High

    CVE-2009-3349

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Datavore Gyro 5.0 allows remote attackers to execute arbitrary SQL commands via the cid parameter in a cat action to the home component.

    Source:OoN_Boy
    Published:24 Sept 2009
    4.3
    Medium

    CVE-2009-3348

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Datavore Gyro 5.0 allows remote attackers to inject arbitrary web script or HTML via the cid parameter in a cat action to the home component.

    Source:OoN_Boy
    Published:24 Sept 2009
    7.5
    High

    CVE-2009-3343

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in details.asp in HotWeb Rentals allows remote attackers to execute arbitrary SQL commands via the PropId parameter.

    Source:R3d-D3V!L
    Published:24 Sept 2009
    7.5
    High

    CVE-2009-3342

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in frontend/assets/ajax/checkusername.php in the AlphaUserPoints (com_alphauserpoints) component 1.5.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the username2points parameter.

    Source:jdc
    Published:24 Sept 2009