4.3
    Medium

    CVE-2009-2965

    Last Modified: 6 Oct 2014

    Cross-site scripting (XSS) vulnerability in entry/index.jsp in Radvision Scopia 5.7, and possibly other versions before SD 7.0.100, allows remote attackers to inject arbitrary web script or HTML via the page parameter.

    Source:Francesco Bianchino
    Published:25 Aug 2009
    9.3
    Critical

    CVE-2009-2961

    Last Modified: 17 Sept 2010

    Stack-based buffer overflow in Thaddy de Konng KOL Player 1.0 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long URL in a .MP3 playlist file.

    Source:Evil.Man
    Published:25 Aug 2009
    7.5
    High

    CVE-2009-2960

    Last Modified: 23 Apr 2026

    CuteFlow 2.10.3 and 2.11.0_c does not properly restrict access to pages/edituser.php, which allows remote attackers to modify usernames and passwords via a direct request.

    Source:Hever Costa Rocha
    Published:25 Aug 2009
    4.3
    Medium

    CVE-2009-2958

    Last Modified: 23 Apr 2026

    The tftp_request function in tftp.c in dnsmasq before 2.50, when --enable-tftp is used, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a TFTP read (aka RRQ) request with a malformed blksize option.

    Source:Core Security
    Published:31 Aug 2009
    6.8
    Medium

    CVE-2009-2957

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the tftp_request function in tftp.c in dnsmasq before 2.50, when --enable-tftp is used, might allow remote attackers to execute arbitrary code via a long filename in a TFTP packet, as demonstrated by a read (aka RRQ) request.

    Source:Core Security
    Published:31 Aug 2009
    5
    Medium

    CVE-2009-2953

    Last Modified: 6 Jan 2017

    Mozilla Firefox 3.0.6 through 3.0.13, and 3.5.x, allows remote attackers to cause a denial of service (CPU consumption) via JavaScript code with a long string value for the hash property (aka location.hash), a related issue to CVE-2008-5715.

    Source:Jeremy Brown
    Published:21 Aug 2009
    4.3
    Medium

    CVE-2009-2937

    Last Modified: 7 May 2014

    Cross-site scripting (XSS) vulnerability in Planet 2.0 and Planet Venus allows remote attackers to inject arbitrary web script or HTML via the SRC attribute of an IMG element in a feed.

    Source:Steve Kemp
    Published:18 Sept 2009
    7.5
    High

    CVE-2009-2936

    Last Modified: 19 Dec 2014

    The Command Line Interface (aka Server CLI or administration interface) in the master process in the reverse proxy server in Varnish before 2.1.0 does not require authentication for commands received through a TCP port, which allows remote attackers to (1) execute arbitrary code via a vcl.inline directive that provides a VCL configuration file containing inline C code; (2) change the ownership of the master process via param.set, stop, and start directives; (3) read the initial line of an arbitrary file via a vcl.load directive; or (4) conduct cross-site request forgery (CSRF) attacks that leverage a victim's location on a trusted network and improper input validation of directives. NOTE: the vendor disputes this report, saying that it is "fundamentally misguided and pointless.

    Source:Patrick Webster
    Published:5 Apr 2010
    9.3
    Critical

    CVE-2009-2934

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in xaudio.dll in Programmed Integration PIPL 2.5.0 and 2.5.0D allow remote attackers to execute arbitrary code via a long string in a (1) .pls or (2) .pl playlist file.

    Source:mr_me
    Published:21 Aug 2009
    4.3
    Medium

    CVE-2009-2930

    Last Modified: 11 Sept 2014

    Cross-site scripting (XSS) vulnerability in the Search feature in elka CMS (aka Elkapax) allows remote attackers to inject arbitrary web script or HTML via the q parameter to the default URI.

    Source:Isfahan
    Published:21 Aug 2009
    7.5
    High

    CVE-2009-2929

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in TGS Content Management 0.x allow remote attackers to execute arbitrary SQL commands via the (1) tgs_language_id, (2) tpl_dir, (3) referer, (4) user-agent, (5) site, (6) option, (7) db_optimization, (8) owner, (9) admin_email, (10) default_language, and (11) db_host parameters to cms/index.php; and the (12) cmd, (13) s_dir, (14) minutes, (15) s_mask, (16) test3_mp, (17) test15_file1, (18) submit, (19) brute_method, (20) ftp_server_port, (21) userfile14, (22) subj, (23) mysql_l, (24) action, and (25) userfile1 parameters to cms/frontpage_ception.php. NOTE: some of these parameters may be applicable only in nonstandard versions of the product, and cms/frontpage_ception.php may be cms/frontpage_caption.php in all released versions.

    Source:[]ViZiOn
    Published:21 Aug 2009
    4.3
    Medium

    CVE-2009-2928

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in login.php in TGS Content Management 0.x allows remote attackers to inject arbitrary web script or HTML via the previous_page parameter, a different vector than CVE-2008-6839.

    Source:[]ViZiOn
    Published:21 Aug 2009
    7.5
    High

    CVE-2009-2927

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in DetailFile.php in DigitalSpinners DS CMS 1.0 allows remote attackers to execute arbitrary SQL commands via the nFileId parameter.

    Source:Mr.tro0oqy
    Published:21 Aug 2009
    7.5
    High

    CVE-2009-2926

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in PHP Competition System BETA 0.84 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) day parameter to show_matchs.php and (2) pageno parameter to persons.php.

    Source:Mr.SQL
    Published:21 Aug 2009
    7.8
    High

    CVE-2009-2925

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in DJcalendar.cgi in DJCalendar allows remote attackers to read arbitrary files via a .. (dot dot) in the TEMPLATE parameter.

    Source:cibbao
    Published:21 Aug 2009
    7.5
    High

    CVE-2009-2924

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Videos Broadcast Yourself 2 allow remote attackers to execute arbitrary SQL commands via the (1) UploadID parameter to videoint.php, and possibly the (2) cat_id parameter to catvideo.php and (3) uid parameter to cviewchannels.php.

    Source:Mr.SQL
    Published:21 Aug 2009
    5
    Medium

    CVE-2009-2923

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in BitmixSoft PHP-Lance 1.52 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) language parameter to show.php and (2) in parameter to advanced_search.php.

    Source:jetli007
    Published:21 Aug 2009
    7.8
    High

    CVE-2009-2922

    Last Modified: 23 Apr 2026

    Absolute path traversal vulnerability in pixaria.image.php in Pixaria Gallery 2.0.0 through 2.3.5 allows remote attackers to read arbitrary files via a base64-encoded file parameter.

    Source:Qabandi
    Published:21 Aug 2009
    7.5
    High

    CVE-2009-2921

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in login.php in MOC Designs PHP News 1.1 allow remote attackers to execute arbitrary SQL commands via the (1) newsuser parameter (User field) and (2) newspassword parameter (Password field).

    Source:SirGod
    Published:21 Aug 2009
    4.3
    Medium

    CVE-2009-2920

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Elvin 1.2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) component and (2) priority parameters to buglist.php; and the (3) Username (4) E-mail, (5) Pass, and (6) Confirm pass fields to createaccount.php.

    Source:599eme Man
    Published:21 Aug 2009
    2.1
    Low

    CVE-2009-2918

    Last Modified: 23 Apr 2026

    The tgbvpn.sys driver in TheGreenBow IPSec VPN Client 4.61.003 allows local users to cause a denial of service (NULL pointer dereference and system crash) via a crafted request to the 0x80000034 IOCTL, probably involving an input or output buffer size of 0.

    Source:Evilcry
    Published:21 Aug 2009
    4.3
    Medium

    CVE-2009-2917

    Last Modified: 17 Sept 2010

    Stack-based buffer overflow in ImTOO MPEG Encoder 3.1.53 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted string in a (1) .cue or (2) .m3u playlist file.

    Source:opt!x hacker
    Published:21 Aug 2009
    7.5
    High

    CVE-2009-2915

    Last Modified: 4 May 2014

    SQL injection vulnerability in 2fly_gift.php in 2FLY Gift Delivery System 6.0 allows remote attackers to execute arbitrary SQL commands via the gameid parameter in a content action.

    Source:Securitylab.ir
    Published:21 Aug 2009
    4.3
    Medium

    CVE-2009-2907

    Last Modified: 18 Jun 2014

    Multiple cross-site scripting (XSS) vulnerabilities in SpringSource tc Server 6.0.20.B and earlier, Application Management Suite (AMS) before 2.0.0.SR4, Hyperic HQ Open Source before 4.2.x, Hyperic HQ 4.0 Enterprise before 4.0.3.2, and Hyperic HQ 4.1 Enterprise before 4.1.2.1 allow remote attackers to inject arbitrary web script or HTML via the description field and unspecified "input fields."

    Source:Aaron Kulick
    Published:24 Mar 2010
    3.5
    Low

    CVE-2009-2898

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Alerts list feature in the web interface in SpringSource Hyperic HQ 3.2.x before 3.2.6.1, 4.0.x before 4.0.3.1, 4.1.x before 4.1.2.1, and 4.2-beta1; Application Management Suite (AMS) 2.0.0.SR3; and tc Server 6.0.20.B allows remote authenticated users to inject arbitrary web script or HTML via the Description field. NOTE: some of these details are obtained from third party information.

    Source:CoreLabs
    Published:13 Oct 2009
    9.3
    Critical

    CVE-2009-2896

    Last Modified: 23 Apr 2026

    Buffer overflow in KMplayer 2.9.4.1433 and earlier allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a long string in a subtitle (.srt) playlist file. NOTE: some of these details are obtained from third party information.

    Source:b3hz4d
    Published:20 Aug 2009
    7.5
    High

    CVE-2009-2895

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in rss.php in Ultimate Regnow Affiliate (URA) 3.0 allows remote attackers to execute arbitrary SQL commands via the cat parameter.

    Source:Chip d3 bi0s
    Published:20 Aug 2009
    7.5
    High

    CVE-2009-2894

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Ebay Clone 2009 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to product_desc.php, and the cid parameter to (2) showcategory.php and (3) gallery.php.

    Source:Hamza 'MizoZ' N.
    Published:20 Aug 2009
    4.3
    Medium

    CVE-2009-2893

    Last Modified: 30 Apr 2014

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in XZero Community Classifieds 4.97.8 allow remote attackers to inject arbitrary web script or HTML via (1) the postevent parameter in a post action or (2) the _xzcal_y parameter.

    Source:Moudi
    Published:20 Aug 2009
    7.5
    High

    CVE-2009-2892

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in header.php in Scripteen Free Image Hosting Script 2.3 allow remote attackers to execute arbitrary SQL commands via a (1) cookid or (2) cookgid cookie.

    Source:Coksnuss
    Published:20 Aug 2009
    7.5
    High

    CVE-2009-2891

    Last Modified: 6 Oct 2014

    SQL injection vulnerability in list.php in PHP Scripts Now Riddles allows remote attackers to execute arbitrary SQL commands via the catid parameter.

    Source:Moudi
    Published:20 Aug 2009
    4.3
    Medium

    CVE-2009-2890

    Last Modified: 6 Oct 2014

    Cross-site scripting (XSS) vulnerability in results.php in PHP Scripts Now Riddles allows remote attackers to inject arbitrary web script or HTML via the searchquery parameter.

    Source:Moudi
    Published:20 Aug 2009
    4.3
    Medium

    CVE-2009-2889

    Last Modified: 25 Sept 2014

    Cross-site scripting (XSS) vulnerability in index.php in PHP Scripts Now Hangman allows remote attackers to inject arbitrary web script or HTML via the letters parameter.

    Source:Moudi
    Published:20 Aug 2009
    7.5
    High

    CVE-2009-2888

    Last Modified: 25 Sept 2014

    SQL injection vulnerability in index.php in PHP Scripts Now Hangman allows remote attackers to execute arbitrary SQL commands via the n parameter.

    Source:Moudi
    Published:20 Aug 2009
    7.5
    High

    CVE-2009-2885

    Last Modified: 6 Oct 2014

    SQL injection vulnerability in bios.php in PHP Scripts Now World's Tallest Buildings allows remote attackers to execute arbitrary SQL commands via the rank parameter.

    Source:599eme Man
    Published:20 Aug 2009
    4.3
    Medium

    CVE-2009-2884

    Last Modified: 6 Oct 2014

    Cross-site scripting (XSS) vulnerability in bios.php in PHP Scripts Now World's Tallest Buildings allows remote attackers to inject arbitrary web script or HTML via the rank parameter.

    Source:599eme Man
    Published:20 Aug 2009
    6.8
    Medium

    CVE-2009-2883

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin/login.php in SaphpLesson 4.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the cp_username parameter, related to an error in the CleanVar function in includes/functions.php.

    Source:SwEET-DeViL
    Published:20 Aug 2009
    4.3
    Medium

    CVE-2009-2882

    Last Modified: 30 Apr 2014

    Multiple cross-site scripting (XSS) vulnerabilities in PG MatchMaking allow remote attackers to inject arbitrary web script or HTML via the show parameter to (1) browse_ladies.php and (2) browse_men.php, the (3) gender parameter to search.php, and the (4) id parameter to services.php.

    Source:Moudi
    Published:20 Aug 2009
    7.5
    High

    CVE-2009-2881

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Basilic 1.5.13 allow remote attackers to execute arbitrary SQL commands via the idAuthor parameter to (1) index.php and possibly (2) allpubs.php in publications/.

    Source:NoGe
    Published:20 Aug 2009
    6.8
    Medium

    CVE-2009-2852

    Last Modified: 23 Apr 2026

    WP-Syntax plugin 0.9.1 and earlier for Wordpress, with register_globals enabled, allows remote attackers to execute arbitrary PHP code via the test_filter[wp_head] array parameter to test/index.php, which is used in a call to the call_user_func_array function.

    Source:Raz0r
    Published:18 Aug 2009
    4.3
    Medium

    CVE-2009-2851

    Last Modified: 4 May 2017

    Cross-site scripting (XSS) vulnerability in the administrator interface in WordPress before 2.8.2 allows remote attackers to inject arbitrary web script or HTML via a comment author URL.

    Source:superfreakaz0rz
    Published:20 Feb 2009
    4.9
    Medium

    CVE-2009-2847

    Last Modified: 23 Apr 2026

    The do_sigaltstack function in kernel/signal.c in Linux kernel 2.4 through 2.4.37 and 2.6 before 2.6.31-rc5, when running on 64-bit systems, does not clear certain padding bytes from a structure, which allows local users to obtain sensitive information from the kernel stack via the sigaltstack function.

    Source:Jon Oberheide
    Published:31 Jul 2009
    4.3
    Medium

    CVE-2009-2820

    Last Modified: 23 Apr 2026

    The web interface in CUPS before 1.4.2, as used on Apple Mac OS X before 10.6.2 and other platforms, does not properly handle (1) HTTP headers and (2) HTML templates, which allows remote attackers to conduct cross-site scripting (XSS) attacks and HTTP response splitting attacks via vectors related to (a) the product's web interface, (b) the configuration of the print system, and (c) the titles of printed jobs, as demonstrated by an XSS attack that uses the kerberos parameter to the admin program, and leverages attribute injection and HTTP Parameter Pollution (HPP) issues.

    Source:Aaron Sigel
    Published:9 Nov 2009
    9.3
    Critical

    CVE-2009-2817

    Last Modified: 27 Oct 2016

    Buffer overflow in Apple iTunes before 9.0.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted .pls file.

    Source:S2 Crew
    Published:24 Sept 2009
    4.6
    Medium

    CVE-2009-2793

    Last Modified: 15 Nov 2017

    The kernel in NetBSD, probably 5.0.1 and earlier, on x86 platforms does not properly handle a pre-commit failure of the iret instruction, which might allow local users to gain privileges via vectors related to a tempEIP pseudocode variable that is outside of the code-segment limits.

    Source:Tavis Ormandy
    Published:18 Sept 2009
    7.5
    High

    CVE-2009-2792

    Last Modified: 14 Nov 2016

    Directory traversal vulnerability in plugings/pagecontent.php in Really Simple CMS (RSCMS) 0.3a allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the PT parameter.

    Source:SirGod
    Published:17 Aug 2009
    7.5
    High

    CVE-2009-2791

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in pda_projects.php in WebDynamite ProjectButler 1.5.0 allows remote attackers to execute arbitrary PHP code via a URL in the offset parameter.

    Source:cr4wl3r
    Published:17 Aug 2009
    7.5
    High

    CVE-2009-2790

    Last Modified: 30 Apr 2014

    SQL injection vulnerability in cat_products.php in SoftBiz Dating Script allows remote attackers to execute arbitrary SQL commands via the cid parameter. NOTE: this might overlap CVE-2006-3271.4.

    Source:MizoZ
    Published:17 Aug 2009
    7.5
    High

    CVE-2009-2788

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Mobilelib GOLD 3 allow remote attackers to execute arbitrary SQL commands via the (1) adminName parameter to cp/auth.php, (2) cid parameter to artcat.php, and (3) catid parameter to show.php.

    Source:SwEET-DeViL
    Published:17 Aug 2009
    6.8
    Medium

    CVE-2009-2787

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in include/reputation/rep_profile.php in the Reputation plugin 2.2.4, 2.2.3, 2.0.4, and earlier for PunBB, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the pun_user[language] parameter.

    Source:Dante90
    Published:17 Aug 2009