7.2
    High

    CVE-2009-3233

    Last Modified: 23 Apr 2026

    changetrack 4.3 allows local users to execute arbitrary commands via CRLF sequences and shell metacharacters in a filename in a directory that is checked by changetrack.

    Source:Rick
    Published:17 Sept 2009
    7.5
    High

    CVE-2009-3226

    Last Modified: 30 Apr 2014

    SQL injection vulnerability in index.php in AlmondSoft Almond Classifieds Ads Enterprise and Almond Affiliate Network Classifieds allows remote attackers to execute arbitrary SQL commands via the replid parameter in a manw_repl add_form action. NOTE: some of these details are obtained from third party information.

    Source:Moudi
    Published:16 Sept 2009
    4.3
    Medium

    CVE-2009-3225

    Last Modified: 30 Apr 2014

    Multiple cross-site scripting (XSS) vulnerabilities in AlmondSoft Almond Classifieds Wap and Pro, and possibly Almond Affiliate Network Classifieds, allow remote attackers to inject arbitrary web script or HTML via (1) the page parameter in a browse action to index.php or (2) the addr parameter to gmap.php. NOTE: some of these details are obtained from third party information.

    Source:Moudi
    Published:16 Sept 2009
    7.5
    High

    CVE-2009-3224

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Super Mod System, when using the 68 Classifieds 3.1 Core System, allows remote attackers to execute arbitrary SQL commands via the s parameter.

    Source:MizoZ
    Published:16 Sept 2009
    6.5
    Medium

    CVE-2009-3223

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in ppc-add-keywords.php in Inout Adserver allows remote authenticated users to execute arbitrary SQL commands via the id parameter.

    Source:boom3rang
    Published:16 Sept 2009
    4.3
    Medium

    CVE-2009-3222

    Last Modified: 25 Sept 2014

    Cross-site scripting (XSS) vulnerability in index.php in FreeWebScriptz Honest Traffic (FWSHT) 1.x allows remote attackers to inject arbitrary web script or HTML via the msg parameter.

    Source:Moudi
    Published:16 Sept 2009
    9.3
    Critical

    CVE-2009-3221

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Audio Lib Player (ALP) allows remote attackers to execute arbitrary code via a long URL in a .m3u playlist file.

    Source:blake
    Published:16 Sept 2009
    7.5
    High

    CVE-2009-3220

    Last Modified: 30 Apr 2014

    PHP remote file inclusion vulnerability in cp_html2txt.php in All In One Control Panel (AIOCP) 1.4.001 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.

    Source:Hadi Kiamarsi
    Published:16 Sept 2009
    6.8
    Medium

    CVE-2009-3219

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in a.php in AR Web Content Manager (AWCM) 2.1, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the a parameter.

    Source:SwEET-DeViL
    Published:16 Sept 2009
    6.8
    Medium

    CVE-2009-3218

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in control/login.php in AR Web Content Manager (AWCM) 2.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the username parameter.

    Source:SwEET-DeViL
    Published:16 Sept 2009
    7.5
    High

    CVE-2009-3217

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the admin module in iWiccle 1.01 allows remote attackers to execute arbitrary SQL commands via the member_id parameter in an edit_user action to index.php.

    Source:SirGod
    Published:16 Sept 2009
    4.3
    Medium

    CVE-2009-3216

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in iWiccle 1.01, when magic_quotes_gpc is disabled, allow remote attackers to read arbitrary files via a .. (dot dot) in (1) the show parameter to the admin module, reachable through index.php; or (2) the module parameter to index.php.

    Source:SirGod
    Published:16 Sept 2009
    7.5
    High

    CVE-2009-3215

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in IXXO Cart Standalone before 3.9.6.1, and the IXXO Cart component for Joomla! 1.0.x, allows remote attackers to execute arbitrary SQL commands via the parent parameter.

    Source:sm0k3
    Published:16 Sept 2009
    9.3
    Critical

    CVE-2009-3214

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in Photodex ProShow Gold 4.0.2549 allow remote attackers to execute arbitrary code via a crafted Slideshow project (.psh) file, related to the (1) cell[n].images[m].image and (2) cell[n].sound.file fields.

    Source:corelanc0d3r
    Published:16 Sept 2009
    9.3
    Critical

    CVE-2009-3213

    Last Modified: 17 Sept 2010

    Stack-based buffer overflow in broid 1.0 Beta 3a allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long string in a .mp3 file.

    Source:hack4love
    Published:16 Sept 2009
    6.8
    Medium

    CVE-2009-3211

    Last Modified: 3 May 2018

    Directory traversal vulnerability in VivaPrograms Infinity Script 2.x.x, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the options[style_dir] parameter to the default URI.

    Source:SwEET-DeViL
    Published:16 Sept 2009
    7.5
    High

    CVE-2009-3209

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in remove.php in PHP eMail Manager 3.3.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.

    Source:MuShTaQ
    Published:16 Sept 2009
    7.5
    High

    CVE-2009-3208

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in phpfreeBB 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to permalink.php and (2) year parameter to index.php.

    Source:Moudi
    Published:16 Sept 2009
    7.5
    High

    CVE-2009-3205

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in main.php in CBAuthority allows remote attackers to execute arbitrary SQL commands via the id parameter in a view_product action.

    Source:Angela Chang
    Published:16 Sept 2009
    7.5
    High

    CVE-2009-3203

    Last Modified: 28 Nov 2016

    SQL injection vulnerability in store.php in AJ Auction Pro OOPD 2.x allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:NoGe
    Published:16 Sept 2009
    4.3
    Medium

    CVE-2009-3202

    Last Modified: 10 Oct 2016

    Cross-site scripting (XSS) vulnerability in search.php in ULoKI PHP Forum 2.1 allows remote attackers to inject arbitrary web script or HTML via the term parameter.

    Source:Moudi
    Published:16 Sept 2009
    4.3
    Medium

    CVE-2009-3201

    Last Modified: 23 Apr 2026

    Integer overflow in Media Player Classic 6.4.9 allows user-assisted remote attackers to cause a denial of service (application crash) via a MIDI file (.mid) with a malformed header, which triggers a buffer overflow, a different vulnerability than CVE-2007-4940.

    Source:PLATEN
    Published:15 Sept 2009
    5
    Medium

    CVE-2009-3199

    Last Modified: 23 Apr 2026

    Uebimiau Webmail 3.2.0-2.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database with usernames and password hashes via a direct request for system_admin/admin.ucf.

    Source:Septemb0x
    Published:15 Sept 2009
    4.3
    Medium

    CVE-2009-3196

    Last Modified: 5 Oct 2014

    Cross-site scripting (XSS) vulnerability in index.php in JCE-Tech PHP Video Script allows remote attackers to inject arbitrary web script or HTML via the key parameter.

    Source:Moudi
    Published:15 Sept 2009
    4.3
    Medium

    CVE-2009-3195

    Last Modified: 5 Oct 2014

    Multiple cross-site scripting (XSS) vulnerabilities in JCE-Tech Auction RSS Content Script 3.0 allow remote attackers to inject arbitrary web script or HTML via the id parameter to (1) rss.php and (2) search.php.

    Source:Moudi
    Published:15 Sept 2009
    4.3
    Medium

    CVE-2009-3194

    Last Modified: 5 Oct 2014

    Cross-site scripting (XSS) vulnerability in index.php in JCE-Tech SearchFeed Script allows remote attackers to inject arbitrary web script or HTML via the search parameter.

    Source:Moudi
    Published:15 Sept 2009
    7.5
    High

    CVE-2009-3193

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the DigiFolio (com_digifolio) component 1.52 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a project action to index.php.

    Source:v3n0m
    Published:15 Sept 2009
    4.3
    Medium

    CVE-2009-3191

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in PAD Site Scripts 3.6 allow remote attackers to inject arbitrary web script or HTML via the cat parameter to (1) rss.php and (2) opml.php.

    Source:Mr.SQL
    Published:15 Sept 2009
    7.5
    High

    CVE-2009-3190

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in PAD Site Scripts 3.6 allow remote attackers to execute arbitrary SQL commands via the (1) search parameter to list.php and (2) cat parameter to rss.php.

    Source:Mr.SQL
    Published:15 Sept 2009
    4.3
    Medium

    CVE-2009-3189

    Last Modified: 3 Oct 2014

    Cross-site scripting (XSS) vulnerability in search.php in DigiOz Guestbook 1.7.2 allows remote attackers to inject arbitrary web script or HTML via the search_term parameter.

    Source:Moudi
    Published:15 Sept 2009
    7.5
    High

    CVE-2009-3188

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in save.php in phpSANE 0.5.0 allows remote attackers to execute arbitrary PHP code via a URL in the file_save parameter.

    Source:CoBRa_21
    Published:15 Sept 2009
    4.3
    Medium

    CVE-2009-3187

    Last Modified: 3 Oct 2014

    Cross-site scripting (XSS) vulnerability in gamelist.php in Stand Alone Arcade 1.1 allows remote attackers to inject arbitrary web script or HTML via the cat parameter.

    Source:Moudi
    Published:15 Sept 2009
    4.3
    Medium

    CVE-2009-3186

    Last Modified: 5 May 2014

    Multiple cross-site scripting (XSS) vulnerabilities in VideoGirls BiZ allow remote attackers to inject arbitrary web script or HTML via the (1) t parameter to forum.php, (2) profile_name parameter to profile.php, and (3) p parameter to view.php.

    Source:Moudi
    Published:15 Sept 2009
    7.5
    High

    CVE-2009-3185

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in plugin.php in the Crazy Star plugin 2.0 for Discuz! allows remote authenticated users to execute arbitrary SQL commands via the fmid parameter in a view action.

    Source:ZhaoHuAn
    Published:15 Sept 2009
    7.5
    High

    CVE-2009-3184

    Last Modified: 3 Oct 2014

    Multiple SQL injection vulnerabilities in index.php in Pirates of The Caribbean in the E-Gold Game Series allow remote attackers to execute arbitrary SQL commands via the (1) x and (2) y parameters.

    Source:Moudi
    Published:15 Sept 2009
    6.8
    Medium

    CVE-2009-3182

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in admin/editor/filemanager/browser.html in Anantasoft Gazelle CMS 1.0 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in user/File/.

    Source:RoMaNcYxHaCkEr
    Published:11 Sept 2009
    5
    Medium

    CVE-2009-3181

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in Anantasoft Gazelle CMS 1.0 allows remote attackers to overwrite arbitrary files via a .. (dot dot) in the customizetemplate parameter in a direct request to admin/settemplate.php.

    Source:IHTeam
    Published:11 Sept 2009
    7.5
    High

    CVE-2009-3180

    Last Modified: 23 Apr 2026

    Anantasoft Gazelle CMS 1.0 allows remote attackers to conduct a password reset for other users via a modified user parameter to renew.php.

    Source:IHTeam
    Published:11 Sept 2009
    7.5
    High

    CVE-2009-3175

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Model Agency Manager PRO (formerly Modeling Agency Content Management Script) allow remote attackers to execute arbitrary SQL commands via the user_id parameter to (1) view.php, (2) photos.php, and (3) motm.php; and the (4) id parameter to forum_message.php.

    Source:R3d-D3V!L
    Published:11 Sept 2009
    7.5
    High

    CVE-2009-3174

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in fonctions_racine.php in OBOphiX 2.7.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the chemin_lib parameter.

    Source:EA Ngel
    Published:11 Sept 2009
    6.8
    Medium

    CVE-2009-3173

    Last Modified: 6 Jan 2017

    Unrestricted file upload vulnerability in admin/add_album.php in The Rat CMS Alpha 2 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in images/.

    Source:Securitylab.ir
    Published:11 Sept 2009
    4.3
    Medium

    CVE-2009-3171

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Anantasoft Gazelle CMS 1.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) user parameter to user.php or (2) lookup parameter to search.php.

    Source:IHTeam
    Published:11 Sept 2009
    9.3
    Critical

    CVE-2009-3170

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in AIMP2 Audio Converter 2.53 (build 330) and earlier allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long File1 argument in a (1) .pls or (2) .m3u playlist file.

    Source:mr_me
    Published:11 Sept 2009
    4.3
    Medium

    CVE-2009-3167

    Last Modified: 24 Jan 2017

    Directory traversal vulnerability in index.php in Anantasoft Gazelle CMS 1.0, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the template parameter.

    Source:fuzion
    Published:11 Sept 2009
    4.3
    Medium

    CVE-2009-3162

    Last Modified: 12 Sept 2014

    Cross-site scripting (XSS) vulnerability in Multi Website 1.5 allows remote attackers to inject arbitrary web script or HTML via the search parameter in a search action to the default URI.

    Source:599eme Man
    Published:10 Sept 2009
    7.5
    High

    CVE-2009-3158

    Last Modified: 23 Apr 2026

    admin/files.php in simplePHPWeb 0.2 does not require authentication, which allows remote attackers to perform unspecified administrative actions via unknown vectors. NOTE: some of these details are obtained from third party information.

    Source:SirGod
    Published:10 Sept 2009
    4.3
    Medium

    CVE-2009-3155

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in gmap.php in the Almond Classifieds (com_aclassf) component 7.5 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the addr parameter.

    Source:Moudi
    Published:10 Sept 2009
    7.5
    High

    CVE-2009-3154

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Almond Classifieds (com_aclassf) component 7.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the replid parameter in a manw_repl add_form action to index.php, a different vector than CVE-2009-2567.

    Source:Moudi
    Published:10 Sept 2009
    4.3
    Medium

    CVE-2009-3153

    Last Modified: 15 Sept 2014

    Multiple cross-site scripting (XSS) vulnerabilities in x10 MP3 Search engine 1.6.5 allow remote attackers to inject arbitrary web script or HTML via the (1) pic_id parameter to includes/video_ad.php, (2) category parameter to linkvideos_listing.php, id parameter to (3) templates/header1.php and (4) mp3/lyrics.php, key parameter to (5) video_listing.php and (6) adult/video_listing.php, and name parameter to (7) mp3/embed.php and (8) mp3/info.php.

    Source:Moudi
    Published:10 Sept 2009
    4.3
    Medium

    CVE-2009-3152

    Last Modified: 30 Apr 2014

    Multiple cross-site scripting (XSS) vulnerabilities in becommunity/community/index.php in NTSOFT BBS E-Market Professional allow remote attackers to inject arbitrary web script or HTML via the (1) page, (2) bt_code, and (3) b_no parameters in a board view action.

    Source:Ivan Sanchez
    Published:10 Sept 2009