7.5
    High

    CVE-2009-2634

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in toolbar_ext.php in the MediaLibrary (com_media_library) component 1.5.3 Basic for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Source:Mehmet Ince
    Published:28 Jul 2009
    7.5
    High

    CVE-2009-2633

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in toolbar_ext.php in the VehicleManager (com_vehiclemanager) component 1.0 Basic for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Source:Mehmet Ince
    Published:28 Jul 2009
    7.5
    High

    CVE-2009-2629

    Last Modified: 16 Apr 2011

    Buffer underflow in src/http/ngx_http_parse.c in nginx 0.1.0 through 0.5.37, 0.6.x before 0.6.39, 0.7.x before 0.7.62, and 0.8.x before 0.8.15 allows remote attackers to execute arbitrary code via crafted HTTP requests.

    Source:Aaron Conole
    Published:14 Sept 2009
    6.4
    Medium

    CVE-2009-2626

    Last Modified: 1 Dec 2016

    The zend_restore_ini_entry_cb function in zend_ini.c in PHP 5.3.0, 5.2.10, and earlier versions allows context-specific attackers to obtain sensitive information (memory contents) and cause a PHP crash by using the ini_set function to declare a variable, then using the ini_restore function to restore the variable.

    Source:Maksymilian Arciemowicz
    Published:1 Dec 2009
    5
    Medium

    CVE-2009-2620

    Last Modified: 10 Oct 2025

    src/remote/server.cpp in fbserver.exe in Firebird SQL 1.5 before 1.5.6, 2.0 before 2.0.6, 2.1 before 2.1.3, and 2.5 before 2.5 Beta 2 allows remote attackers to cause a denial of service (daemon crash) via a malformed op_connect_request message that triggers an infinite loop or NULL pointer dereference.

    Source:Core Security
    Published:28 Jul 2009
    7.5
    High

    CVE-2009-2619

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in login.asp in DataCheck Solutions V-SpacePal allows remote attackers to execute arbitrary SQL commands via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:R3d-D3V!L
    Published:27 Jul 2009
    7.5
    High

    CVE-2009-2618

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Surveys (aka NS-Polls) module in MDPro (MD-Pro) 1.083.x allows remote attackers to execute arbitrary SQL commands via the pollID parameter in a results action to modules.php.

    Source:XaDoS
    Published:27 Jul 2009
    9.3
    Critical

    CVE-2009-2617

    Last Modified: 28 Apr 2014

    Stack-based buffer overflow in medialib.dll in BaoFeng Storm 3.9.62 allows remote attackers to execute arbitrary code via a long pathname in the source attribute of an item element in a .smpl playlist file.

    Source:Jambalaya
    Published:27 Jul 2009
    7.5
    High

    CVE-2009-2614

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in z_admin_login.asp in DataCheck Solutions LinkPal 1.x allows remote attackers to execute arbitrary SQL commands via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:R3d-D3V!L
    Published:27 Jul 2009
    6.8
    Medium

    CVE-2009-2611

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in infusions/last_seen_users_panel/last_seen_users_panel.php in MyFusion (aka MyF) 6 Beta, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the settings[locale] parameter.

    Source:CraCkEr
    Published:27 Jul 2009
    7.5
    High

    CVE-2009-2609

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the amoCourse (com_amocourse) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a category action to index.php.

    Source:Chip d3 bi0s
    Published:27 Jul 2009
    6.8
    Medium

    CVE-2009-2608

    Last Modified: 7 Dec 2016

    Multiple SQL injection vulnerabilities in PHP Address Book 4.0.x allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to delete.php or (2) alphabet parameter to index.php. NOTE: the edit.php and view.php vectors are already covered by CVE-2008-2565.

    Source:YEnH4ckEr
    Published:27 Jul 2009
    7.5
    High

    CVE-2009-2607

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the com_pinboard component for Joomla! allows remote attackers to execute arbitrary SQL commands via the task parameter in a showpic action to index.php.

    Source:Stack
    Published:27 Jul 2009
    5
    Medium

    CVE-2009-2606

    Last Modified: 23 Apr 2026

    ASP Football Pool 2.3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for NFL.mdb.

    Source:ByALBAYX
    Published:27 Jul 2009
    6.8
    Medium

    CVE-2009-2605

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in adminquery.php in Traidnt Up 2.0 allow remote attackers to execute arbitrary SQL commands via (1) trupuser and (2) truppassword cookies to uploadcp/index.php.

    Source:Qabandi
    Published:27 Jul 2009
    7.5
    High

    CVE-2009-2604

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in adminlogin.asp in Zen Help Desk 2.1 allow remote attackers to execute arbitrary SQL commands via the (1) userid (aka username) and (2) PassWord parameters to admin.asp.

    Source:TiGeR-Dz
    Published:27 Jul 2009
    7.5
    High

    CVE-2009-2603

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in index.php in Escon SupportPortal Pro 3.0 allow remote attackers to execute arbitrary SQL commands via the (1) cat and (2) tid parameters.

    Source:OzX
    Published:27 Jul 2009
    5
    Medium

    CVE-2009-2602

    Last Modified: 23 Apr 2026

    R2 Newsletter Lite, Pro, and Stats stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for admin.mdb.

    Source:TiGeR-Dz
    Published:27 Jul 2009
    7.5
    High

    CVE-2009-2601

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Joomlaequipment (aka JUser or com_juser) component 2.0.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a show_profile action to index.php.

    Source:Chip d3 bi0s
    Published:27 Jul 2009
    5
    Medium

    CVE-2009-2600

    Last Modified: 11 Oct 2014

    Multiple directory traversal vulnerabilities in view.php in Webboard 2.90 beta and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in the topic parameter.

    Source:MrDoug
    Published:27 Jul 2009
    7.5
    High

    CVE-2009-2599

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in RadCLASSIFIEDS Gold 2.0 allows remote attackers to execute arbitrary SQL commands via the seller parameter in a search action.

    Source:Br0ly
    Published:27 Jul 2009
    6.5
    Medium

    CVE-2009-2598

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Online Grades & Attendance 3.2.6 and earlier allow (1) remote attackers to execute arbitrary SQL commands via the key parameter in a resetpass action to index.php and (2) remote authenticated users to execute arbitrary SQL commands via the ADD parameter in a mailto action to parents/parents.php.

    Source:YEnH4ckEr
    Published:27 Jul 2009
    4.3
    Medium

    CVE-2009-2595

    Last Modified: 2 May 2014

    Cross-site scripting (XSS) vulnerability in productSearch.html in Censura 2.0.4 and 2.1.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter in a ProductSearch action.

    Source:mark99
    Published:24 Jul 2009
    4.3
    Medium

    CVE-2009-2594

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in censura.php in Censura 1.16.04 allows remote attackers to inject arbitrary web script or HTML via the itemid parameter in a details action.

    Source:Vrs-hCk
    Published:24 Jul 2009
    7.5
    High

    CVE-2009-2593

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in censura.php in Censura 1.16.04 allows remote attackers to execute arbitrary SQL commands via the itemid parameter in a details action.

    Source:Vrs-hCk
    Published:24 Jul 2009
    7.5
    High

    CVE-2009-2591

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the MyAnnonces module for E-Xoopport 3.1 allows remote attackers to execute arbitrary SQL commands via the lid parameter in a viewannonces action to index.php.

    Source:Vrs-hCk
    Published:24 Jul 2009
    4.3
    Medium

    CVE-2009-2588

    Last Modified: 25 Sept 2014

    Multiple cross-site scripting (XSS) vulnerabilities in Hotscripts Type PHP Clone Script allow remote attackers to inject arbitrary web script or HTML via the msg parameter to (1) feedback.php, (2) index.php, and (3) lostpassword.php.

    Source:Moudi
    Published:24 Jul 2009
    4.3
    Medium

    CVE-2009-2587

    Last Modified: 22 Sept 2014

    Multiple cross-site scripting (XSS) vulnerabilities in DragDropCart allow remote attackers to inject arbitrary web script or HTML via the (1) sid parameter to assets/js/ddcart.php, the (2) prefix parameter to includes/ajax/getstate.php, the search parameter to (3) index.php and (4) search.php, the (5) redirect parameter to login.php, and the (6) product parameter to productdetail.php.

    Source:Moudi
    Published:24 Jul 2009
    4.3
    Medium

    CVE-2009-2586

    Last Modified: 22 Sept 2014

    Cross-site scripting (XSS) vulnerability in articles.php in EDGEPHP EZArticles allows remote attackers to inject arbitrary web script or HTML via the title parameter.

    Source:Moudi
    Published:24 Jul 2009
    7.5
    High

    CVE-2009-2585

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Mlffat 2.2 allows remote attackers to execute arbitrary SQL commands via a member cookie in an account editprofile action, a different vector than CVE-2009-1731.

    Source:Qabandi
    Published:24 Jul 2009
    6.5
    Medium

    CVE-2009-2579

    Last Modified: 3 May 2014

    SQL injection vulnerability in reward_points.post.php in the Reward points addon in CS-Cart before 2.0.6 allows remote authenticated users to execute arbitrary SQL commands via the sort_order parameter in a reward_points.userlog action to index.php, a different vulnerability than CVE-2005-4429.2.

    Source:Ryan Dewhurst
    Published:5 Aug 2009
    6.5
    Medium

    CVE-2009-2574

    Last Modified: 23 Apr 2026

    index.php in MiniTwitter 0.2 beta allows remote authenticated users to modify certain options of arbitrary accounts via an opt action.

    Source:YEnH4ckEr
    Published:22 Jul 2009
    6
    Medium

    CVE-2009-2573

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in MiniTwitter 0.2 beta, when magic_quotes_gpc is disabled, allow remote authenticated users to execute arbitrary SQL commands via the (1) user parameter to (a) index.php and (b) rss.php.

    Source:YEnH4ckEr
    Published:22 Jul 2009
    4.3
    Medium

    CVE-2009-2571

    Last Modified: 23 Apr 2014

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in VerliAdmin 0.3.7 and 0.3.8 allow remote attackers to inject arbitrary web script or HTML via (1) the URI, (2) the q parameter, (3) the nick parameter, or (4) the nick parameter in a bantest action.

    Source:TEAMELITE
    Published:22 Jul 2009
    9.3
    Critical

    CVE-2009-2570

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the Symantec.FaxViewerControl.1 ActiveX control in WinFax\DCCFAXVW.DLL in Symantec WinFax Pro 10.03 allows remote attackers to execute arbitrary code via a long argument to the AppendFax method.

    Source:Nine:Situations:Group
    Published:22 Jul 2009
    4.3
    Medium

    CVE-2009-2569

    Last Modified: 6 Jan 2017

    Multiple cross-site scripting (XSS) vulnerabilities in Verlihub Control Panel (VHCP) 1.7e allow remote attackers to inject arbitrary web script or HTML via (1) the nick parameter in a login action to index.php or (2) the URI in a news request to index.html.

    Source:TEAMELITE
    Published:22 Jul 2009
    9.3
    Critical

    CVE-2009-2568

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Sorinara Streaming Audio Player (SAP) 0.9 allows remote attackers to execute arbitrary code via a long string in a playlist (.m3u) file.

    Source:Cyber-Zone
    Published:22 Jul 2009
    7.5
    High

    CVE-2009-2567

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Almond Classifieds (com_aclassf) component 5.6.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.

    Source:InjEctOr5
    Published:22 Jul 2009
    9.3
    Critical

    CVE-2009-2566

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in TFM MMPlayer 2.0, and possibly 2.0.0.30, allows remote attackers to execute arbitrary code via a long string in a playlist (.m3u) file.

    Source:ThE g0bL!N
    Published:21 Jul 2009
    7.2
    High

    CVE-2009-2564

    Last Modified: 23 Apr 2026

    NOS Microsystems getPlus Download Manager, as used in Adobe Reader 1.6.2.36 and possibly other versions, Corel getPlus Download Manager before 1.5.0.48, and possibly other products, installs NOS\bin\getPlus_HelperSvc.exe with insecure permissions (Everyone:Full Control), which allows local users to gain SYSTEM privileges by replacing getPlus_HelperSvc.exe with a Trojan horse program, as demonstrated by use of getPlus Download Manager within Adobe Reader. NOTE: within Adobe Reader, the scope of this issue is limited because the program is deleted and the associated service is not automatically launched after a successful installation and reboot.

    Source:Nine:Situations:Group
    Published:21 Jul 2009
    7.5
    High

    CVE-2009-2558

    Last Modified: 23 Apr 2026

    system/message.php in Admin News Tools 2.5 does not properly restrict access, which allows remote attackers to post news messages via a direct request.

    Source:Securitylab.ir
    Published:21 Jul 2009
    5
    Medium

    CVE-2009-2557

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in system/download.php in Admin News Tools 2.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the fichier parameter.

    Source:Securitylab.ir
    Published:21 Jul 2009
    6.8
    Medium

    CVE-2009-2554

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the search method in jobline.class.php in Jobline (com_jobline) 1.1.2.2, 1.3.1, and possibly earlier versions, a component for Joomla!, allows remote attackers to execute arbitrary SQL commands via the search parameter in a results action to index.php, which invokes the search method from the searchJobPostings function in jobline.php.

    Source:ManhLuat93
    Published:20 Jul 2009
    6.8
    Medium

    CVE-2009-2553

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in comments.php in Super Simple Blog Script 2.5.4, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the entry parameter.

    Source:JIKO
    Published:20 Jul 2009
    6.8
    Medium

    CVE-2009-2552

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in comments.php in Super Simple Blog Script 2.5.4 allow remote attackers to overwrite, include, and execute arbitrary local files via the entry parameter.

    Source:JIKO
    Published:20 Jul 2009
    4.3
    Medium

    CVE-2009-2551

    Last Modified: 29 Apr 2014

    Multiple cross-site scripting (XSS) vulnerabilities in ScriptsEz Easy Image Downloader allow remote attackers to inject arbitrary web script or HTML via the id parameter in a detail action to (1) main.php and possibly (2) demo_page.php.

    Source:Moudi
    Published:20 Jul 2009
    9.3
    Critical

    CVE-2009-2550

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Hamster Audio Player 0.3a allows remote attackers to execute arbitrary code via a long string in a (1) .m3u or (2) .hpl playlist file.

    Source:ThE g0bL!N
    Published:20 Jul 2009
    6.8
    Medium

    CVE-2009-2544

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the Marcelo Costa FileServer component 1.0 for Microsoft Windows Live Messenger and Messenger Plus! Live (MPL) allows remote authenticated users to list arbitrary directories and read arbitrary files via a .. (dot dot) in a pathname.

    Source:joepie91
    Published:20 Jul 2009
    5
    Medium

    CVE-2009-2535

    Last Modified: 23 Apr 2026

    Mozilla Firefox before 2.0.0.19 and 3.x before 3.0.5, SeaMonkey, and Thunderbird allow remote attackers to cause a denial of service (memory consumption and application crash) via a large integer value for the length property of a Select object, a related issue to CVE-2009-1692.

    Source:Thierry Zoller
    Published:15 Jul 2009
    5
    Medium

    CVE-2009-2534

    Last Modified: 23 Apr 2026

    RealNetworks Helix Server and Helix Mobile Server before 13.0.0 allow remote attackers to cause a denial of service (daemon crash) via an RTSP SETUP request that (1) specifies the / URI or (2) lacks a / character in the URI.

    Source:Core Security
    Published:20 Jul 2009