7.5
    High

    CVE-2009-2786

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in reputation.php in the Reputation plugin 2.2.4, 2.2.3, 2.0.4, and earlier for PunBB allows remote attackers to execute arbitrary SQL commands via the poster parameter.

    Source:Dante90
    Published:17 Aug 2009
    9.3
    Critical

    CVE-2009-2784

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in dit.cms 1.3, when register_globals is enabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the path parameter to index.php in (1) install/, (2) menus/left_rightslideopen/, (3) menus/side_pullout/, (4) menus/side_slideopen/, (5) menus/simple/, (6) menus/top_dropdown/, and (7) menus/topside/; the sitemap parameter to index.php in (8) menus/left_rightslideopen/, (9) menus/side_pullout/, (10) menus/side_slideopen/, (11) menus/top_dropdown/, and (12) menus/topside/; and the (13) relPath parameter to index/index.php. NOTE: PHP remote file inclusion vulnerabilities reportedly also exist for some of these vectors.

    Source:SirGod
    Published:17 Aug 2009
    4.3
    Medium

    CVE-2009-2783

    Last Modified: 30 Apr 2014

    Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 2.3.3 allow remote attackers to inject arbitrary web script or HTML via the (1) op parameter to modules/pm/viewpmsg.php and (2) query string to modules/profile/user.php.

    Source:Sense of Security
    Published:17 Aug 2009
    7.5
    High

    CVE-2009-2782

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the JFusion (com_jfusion) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter to index.php.

    Source:Chip d3 bi0s
    Published:17 Aug 2009
    6
    Medium

    CVE-2009-2781

    Last Modified: 2 Jan 2017

    SQL injection vulnerability in forum.php in Arab Portal 2.x, when magic_quotes_gpc is disabled, allows remote authenticated users to execute arbitrary SQL commands via the qc parameter in an addcomment action, a different vector than CVE-2006-1666.

    Source:rEcruit
    Published:17 Aug 2009
    4.3
    Medium

    CVE-2009-2780

    Last Modified: 29 Nov 2016

    Multiple cross-site scripting (XSS) vulnerabilities in 68 Classifieds 4.1 allow remote attackers to inject arbitrary web script or HTML via the (1) cat parameter to category.php, view parameter to (2) login.php and (3) viewlisting.php, page parameter to (4) searchresults.php and (5) toplistings.php, and (6) member parameter to viewmember.php.

    Source:Moudi
    Published:17 Aug 2009
    7.5
    High

    CVE-2009-2779

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in AJ Matrix DNA allows remote attackers to execute arbitrary SQL commands via the id parameter in a productdetail action.

    Source:v3n0m
    Published:17 Aug 2009
    4.3
    Medium

    CVE-2009-2778

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in visitor/view.php in GarageSales Script allows remote attackers to inject arbitrary web script or HTML via the key parameter. NOTE: some of these details are obtained from third party information.

    Source:Moudi
    Published:14 Aug 2009
    7.5
    High

    CVE-2009-2777

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in visitor/view.php in GarageSales Script allows remote attackers to execute arbitrary SQL commands via the key parameter.

    Source:Moudi
    Published:14 Aug 2009
    7.5
    High

    CVE-2009-2776

    Last Modified: 18 Sept 2014

    SQL injection vulnerability in showresult.asp in Smart ASP Survey allows remote attackers to execute arbitrary SQL commands via the catid parameter.

    Source:Moudi
    Published:14 Aug 2009
    7.5
    High

    CVE-2009-2775

    Last Modified: 15 Nov 2016

    SQL injection vulnerability in linkout.php in PHPArcadeScript (PHP Arcade Script) 4.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:MizoZ
    Published:14 Aug 2009
    7.5
    High

    CVE-2009-2774

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in paidbanner.php in PHP Paid 4 Mail Script allows remote attackers to execute arbitrary SQL commands via the ID parameter.

    Source:ThE g0bL!N
    Published:14 Aug 2009
    7.5
    High

    CVE-2009-2773

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in home.php in PHP Paid 4 Mail Script allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.

    Source:int_main();
    Published:14 Aug 2009
    4.3
    Medium

    CVE-2009-2772

    Last Modified: 30 Apr 2014

    Multiple cross-site scripting (XSS) vulnerabilities in PG Roommate Finder Solution allow remote attackers to inject arbitrary web script or HTML via the part parameter to (1) quick_search.php and (2) viewprofile.php.

    Source:Moudi
    Published:14 Aug 2009
    7.5
    High

    CVE-2009-2770

    Last Modified: 23 Apr 2026

    PowerUpload 2.4 allows remote attackers to bypass authentication and gain administrative access via a MIME encoded value of admin for the myadminname cookie.

    Source:InjEctOr5
    Published:14 Aug 2009
    6.8
    Medium

    CVE-2009-2769

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in include/timesheet.php in Ultrize TimeSheet 1.2.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the config[include_dir] parameter.

    Source:NoGe
    Published:14 Aug 2009
    7.2
    High

    CVE-2009-2767

    Last Modified: 6 Sept 2016

    The init_posix_timers function in kernel/posix-timers.c in the Linux kernel before 2.6.31-rc6 allows local users to cause a denial of service (OOPS) or possibly gain privileges via a CLOCK_MONOTONIC_RAW clock_nanosleep call that triggers a NULL pointer dereference.

    Source:Hiroshi Shimamoto
    Published:3 Aug 2009
    7.5
    High

    CVE-2009-2766

    Last Modified: 27 Oct 2016

    httpd.c in httpd in the management GUI in DD-WRT 24 sp1 does not require administrative authentication for programs under cgi-bin/, which allows remote attackers to change settings via HTTP requests.

    Source:gat3way
    Published:14 Aug 2009
    8.3
    High

    CVE-2009-2765

    Last Modified: 27 Oct 2016

    httpd.c in httpd in the management GUI in DD-WRT 24 sp1, and other versions before build 12533, allows remote attackers to execute arbitrary commands via shell metacharacters in a request to a cgi-bin/ URI.

    Source:Metasploit
    Published:14 Aug 2009
    5
    Medium

    CVE-2009-2764

    Last Modified: 23 Apr 2026

    Microsoft Internet Explorer 8.0.7100.0 on Windows 7 RC on the x64 platform allows remote attackers to cause a denial of service (application crash) via a certain DIV element in conjunction with SCRIPT elements that have empty contents and no reference to a valid external script location.

    Source:schnuddelbuddel
    Published:14 Aug 2009
    7.5
    High

    CVE-2009-2762

    Last Modified: 18 Jul 2018

    wp-login.php in WordPress 2.8.3 and earlier allows remote attackers to force a password reset for the first user in the database, possibly the administrator, via a key[] array variable in a resetpass (aka rp) action, which bypasses a check that assumes that $key is not an array.

    Source:iso^kpsbr
    Published:13 Aug 2009
    10
    Critical

    CVE-2009-2754

    Last Modified: 11 Apr 2025

    Integer signedness error in the authentication functionality in librpc.dll in the Informix Storage Manager (ISM) Portmapper service (aka portmap.exe), as used in IBM Informix Dynamic Server (IDS) 10.x before 10.00.TC9 and 11.x before 11.10.TC3 and EMC Legato NetWorker, allows remote attackers to execute arbitrary code via a crafted parameter size that triggers a stack-based buffer overflow.

    Source:ZSploit.com
    Published:5 Mar 2010
    10
    Critical

    CVE-2009-2753

    Last Modified: 11 Apr 2025

    Multiple buffer overflows in the authentication functionality in librpc.dll in the Informix Storage Manager (ISM) Portmapper service (aka portmap.exe), as used in IBM Informix Dynamic Server (IDS) 10.x before 10.00.TC9 and 11.x before 11.10.TC3, allow remote attackers to execute arbitrary code via a crafted parameter size.

    Source:ZSploit.com
    Published:5 Mar 2010
    6.5
    Medium

    CVE-2009-2736

    Last Modified: 23 Apr 2026

    Static code injection vulnerability in admin.php in sun-jester OpenNews 1.0 allows remote authenticated administrators to inject arbitrary PHP code into config.php via the "Overall Width" field in a setconfig action.

    Source:SirGod
    Published:11 Aug 2009
    6.8
    Medium

    CVE-2009-2735

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin.php in sun-jester OpenNews 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the username parameter.

    Source:SirGod
    Published:11 Aug 2009
    7.5
    High

    CVE-2009-2734

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the get_employee function in classweekreport.inc in Achievo before 1.4.0 allows remote attackers to execute arbitrary SQL commands via the userid parameter (aka user_id variable) to dispatch.php.

    Source:Ryan Dewhurst
    Published:16 Oct 2009
    4.3
    Medium

    CVE-2009-2733

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Achievo before 1.4.0 allow remote attackers to inject arbitrary web script or HTML via (1) the scheduler title in the scheduler module, and the (2) atksearch[contractnumber], (3) atksearch_AE_customer[customer], (4) atksearchmode[contracttype], and possibly (5) atksearch[contractname] parameters to the Organization Contracts administration page, reachable through dispatch.php.

    Source:Ryan Dewhurst
    Published:16 Oct 2009
    5
    Medium

    CVE-2009-2732

    Last Modified: 4 May 2014

    The checkHTTPpassword function in http.c in ntop 3.3.10 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an Authorization HTTP header that lacks a : (colon) character in the base64-decoded string.

    Source:Brad Antoniewicz
    Published:8 Aug 2009
    9.3
    Critical

    CVE-2009-2727

    Last Modified: 6 Mar 2011

    Stack-based buffer overflow in the _tt_internal_realpath function in the ToolTalk library (libtt.a) in IBM AIX 5.2.0, 5.3.0, 5.3.7 through 5.3.10, and 6.1.0 through 6.1.3, when the rpc.ttdbserver daemon is enabled in /etc/inetd.conf, allows remote attackers to execute arbitrary code via a long XDR-encoded ASCII string to remote procedure 15.

    Source:Metasploit
    Published:10 Aug 2009
    4.9
    Medium

    CVE-2009-2715

    Last Modified: 27 Oct 2016

    Sun VirtualBox 2.2 through 3.0.2 r49928 allows guest OS users to cause a denial of service (Linux host OS reboot) via a sysenter instruction.

    Source:Tadas Vilkeliskis
    Published:7 Aug 2009
    4.3
    Medium

    CVE-2009-2705

    Last Modified: 5 May 2014

    CA SiteMinder allows remote attackers to bypass cross-site scripting (XSS) protections for J2EE applications via a request containing non-canonical, "overlong Unicode" in place of blacklisted characters.

    Source:Arshan Dabirsiaghi
    Published:11 Aug 2009
    4.3
    Medium

    CVE-2009-2704

    Last Modified: 4 May 2014

    CA SiteMinder allows remote attackers to bypass cross-site scripting (XSS) protections for J2EE applications via a request containing a %00 (encoded null byte).

    Source:Arshan Dabirsiaghi
    Published:11 Aug 2009
    7.8
    High

    CVE-2009-2698

    Last Modified: 23 Apr 2026

    The udp_sendmsg function in the UDP implementation in (1) net/ipv4/udp.c and (2) net/ipv6/udp.c in the Linux kernel before 2.6.19 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via vectors involving the MSG_MORE flag and a UDP socket.

    Source:Andi
    Published:24 Aug 2009
    10
    Critical

    CVE-2009-2694

    Last Modified: 23 Apr 2026

    The msn_slplink_process_msg function in libpurple/protocols/msn/slplink.c in libpurple, as used in Pidgin (formerly Gaim) before 2.5.9 and Adium 1.3.5 and earlier, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) by sending multiple crafted SLP (aka MSNSLP) messages to trigger an overwrite of an arbitrary memory location. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2009-1376.

    Source:Pierre Nogues
    Published:18 Aug 2009
    7.8
    High

    CVE-2009-2692

    Last Modified: 14 Jul 2017

    The Linux kernel 2.6.0 through 2.6.30.4, and 2.4.4 through 2.4.37.4, does not initialize all function pointers for socket operations in proto_ops structures, which allows local users to trigger a NULL pointer dereference and gain privileges by using mmap to map page zero, placing arbitrary code on this page, and then invoking an unavailable operation, as demonstrated by the sendpage operation (sock_sendpage function) on a PF_PPPOX socket.

    Source:Zinx
    Published:13 Aug 2009
    10
    Critical

    CVE-2009-2685

    Last Modified: 27 Oct 2016

    Stack-based buffer overflow in the login form in the management web server in HP Power Manager allows remote attackers to execute arbitrary code via the Login variable.

    Source:Metasploit
    Published:6 Nov 2009
    4.3
    Medium

    CVE-2009-2684

    Last Modified: 27 Oct 2016

    Multiple cross-site scripting (XSS) vulnerabilities in Jetdirect and the Embedded Web Server (EWS) on certain HP LaserJet and Color LaserJet printers, and HP Digital Senders, allow remote attackers to inject arbitrary web script or HTML via the (1) Product_URL or (2) Tech_URL parameter in an Apply action to the support_param.html/config script.

    Source:Digital Security Research Group
    Published:13 Oct 2009
    7.2
    High

    CVE-2009-2669

    Last Modified: 14 Nov 2016

    A certain debugging component in IBM AIX 5.3 and 6.1 does not properly handle the (1) _LIB_INIT_DBG and (2) _LIB_INIT_DBG_FILE environment variables, which allows local users to gain privileges by leveraging a setuid-root program to create an arbitrary root-owned file with world-writable permissions, related to libC.a (aka the XL C++ runtime library) in AIX 5.3 and libc.a in AIX 6.1.

    Source:Marco Ivaldi
    Published:5 Aug 2009
    4.3
    Medium

    CVE-2009-2655

    Last Modified: 23 Apr 2026

    mshtml.dll in Microsoft Internet Explorer 7 and 8 on Windows XP SP3 allows remote attackers to cause a denial of service (application crash) by calling the JavaScript findText method with a crafted Unicode string in the first argument, and only one additional argument, as demonstrated by a second argument of -1.

    Source:Hong10
    Published:3 Aug 2009
    5.8
    Medium

    CVE-2009-2654

    Last Modified: 30 Apr 2014

    Mozilla Firefox before 3.0.13, and 3.5.x before 3.5.2, allows remote attackers to spoof the address bar, and possibly conduct phishing attacks, via a crafted web page that calls window.open with an invalid character in the URL, makes document.write calls to the resulting object, and then calls the stop method during the loading of the error page.

    Source:Juan Pablo Lopez Yacubian
    Published:24 Jul 2009
    4.6
    Medium

    CVE-2009-2653

    Last Modified: 23 Apr 2026

    The NtUserConsoleControl function in win32k.sys in Microsoft Windows XP SP2 and SP3, and Server 2003 before SP1, allows local administrators to bypass unspecified "security software" and gain privileges via a crafted call that triggers an overwrite of an arbitrary memory location. NOTE: the vendor disputes the significance of this report, stating that 'the Administrator to SYSTEM "escalation" is not a security boundary we defend.

    Source:NT Internals
    Published:3 Aug 2009
    9.3
    Critical

    CVE-2009-2650

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in Sorcerer Software MultiMedia Jukebox 4.0 Build 020124 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted (1) .m3u or possibly (2) .pst file.

    Source:hack4love
    Published:30 Jul 2009
    4.7
    Medium

    CVE-2009-2649

    Last Modified: 23 Apr 2026

    The IATA (ata) driver in FreeBSD 6.0 and 8.0, when read access to /dev is available, allows local users to cause a denial of service (kernel panic) via a certain IOCTL request with a large count, which triggers a malloc call with a large value.

    Source:Shaun Colley
    Published:30 Jul 2009
    7.5
    High

    CVE-2009-2642

    Last Modified: 23 Apr 2026

    index.php in Desi Short URL Script 1.0 allows remote attackers to bypass authentication by setting the logged cookie to 1 and the uid cookie to an integer value, as demonstrated by a value of 13.

    Source:N@bilX
    Published:28 Jul 2009
    6.8
    Medium

    CVE-2009-2641

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in app_and_readme/navigator/index.php in School Data Navigator allows remote attackers to execute arbitrary PHP code via a URL in the page parameter. NOTE: this can also be leveraged to include and execute arbitrary local files via .. (dot dot) sequences.

    Source:Br0ly
    Published:28 Jul 2009
    7.5
    High

    CVE-2009-2640

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in cgi/admin.cgi in Interlogy Profile Manager Basic allow remote attackers to execute arbitrary SQL commands via a pmadm cookie in (1) an edittemp action or (2) a users action.

    Source:ZoRLu
    Published:28 Jul 2009
    7.5
    High

    CVE-2009-2639

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin.php in MRCGIGUY The Ticket System 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a viewticket action.

    Source:ThE g0bL!N
    Published:28 Jul 2009
    7.5
    High

    CVE-2009-2638

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the AkoBook (com_akobook) component 2.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the gbid parameter in a reply action to index.php.

    Source:Ab1i
    Published:28 Jul 2009
    7.5
    High

    CVE-2009-2637

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in toolbar_ext.php in the BookLibrary (com_booklibrary) component 1.5.2.4 Basic for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Source:Mehmet Ince
    Published:28 Jul 2009
    7.5
    High

    CVE-2009-2635

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in toolbar_ext.php in the RealEstateManager (com_realestatemanager) component 1.0 Basic for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Source:Mehmet Ince
    Published:28 Jul 2009