9.8
    Critical

    CVE-2009-2382

    Last Modified: 23 Apr 2026

    admin.php in phpMyBlockchecker 1.0.0055 allows remote attackers to bypass authentication and gain administrative access by setting the PHPMYBCAdmin cookie to LOGGEDIN.

    Source:SirGod
    Published:8 Jul 2009
    6.8
    Medium

    CVE-2009-2379

    Last Modified: 28 Nov 2016

    Directory traversal vulnerability in public/index.php in BIGACE Web CMS 2.6 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the cmd parameter.

    Source:CWD@rBe
    Published:8 Jul 2009
    7.5
    High

    CVE-2009-2378

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in formmailer.admin.inc.php in Jax FormMailer 3.0.0 allows remote attackers to execute arbitrary PHP code via a URL in the BASE_DIR[jax_formmailer] parameter.

    Source:ahmadbady
    Published:8 Jul 2009
    4.3
    Medium

    CVE-2009-2377

    Last Modified: 28 Apr 2014

    Buffer overflow in the Avax Vector ActiveX control in avPreview.ocx in AVAX-software Avax Vector ActiveX 1.3 allows remote attackers to cause a denial of service (application crash) via a long PrinterName property.

    Source:Satan_HackerS
    Published:8 Jul 2009
    9.3
    Critical

    CVE-2009-2375

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Photo DVD Maker 8.02, and possibly earlier versions, allows remote attackers to execute arbitrary code via a long File_Name parameter in a .pdm file. NOTE: some of these details are obtained from third party information.

    Source:His0k4
    Published:8 Jul 2009
    7.5
    High

    CVE-2009-2366

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in login.asp in DataCheck Solutions ForumPal FE 1.1 and ForumPal 1.5 allows remote attackers to execute arbitrary SQL commands via the (1) password parameter in 1.1 and (2) p_password parameter in 1.5. NOTE: some of these details are obtained from third party information.

    Source:ThE g0bL!N
    Published:8 Jul 2009
    7.5
    High

    CVE-2009-2365

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in login.asp in DataCheck Solutions GalleryPal FE 1.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:R3d-D3V!L
    Published:8 Jul 2009
    9.3
    Critical

    CVE-2009-2364

    Last Modified: 18 Nov 2010

    Stack-based buffer overflow in Mp3-Nator 2.0 allows remote attackers to execute arbitrary code via (1) a long string in a .plf file and (2) a long string in the listdata.dat file, possibly related to a track entry.

    Source:Muhamad Fadzil Ramli
    Published:8 Jul 2009
    9.3
    Critical

    CVE-2009-2363

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in KUDRSOFT AudioPLUS 2.00.215 allows remote attackers to execute arbitrary code via a .pls playlist file with a playlist entry containing a long File1 argument.

    Source:hack4love
    Published:8 Jul 2009
    9.3
    Critical

    CVE-2009-2362

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in KUDRSOFT AudioPLUS 2.0.0.215 allows remote attackers to execute arbitrary code via a long string in a (1) .lst or (2) .m3u playlist file.

    Source:hack4love
    Published:8 Jul 2009
    7.5
    High

    CVE-2009-2361

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in include/class.staff.php in osTicket before 1.6 RC5 allows remote attackers to execute arbitrary SQL commands via the staff username parameter.

    Source:Adam Baldwin
    Published:8 Jul 2009
    4.3
    Medium

    CVE-2009-2360

    Last Modified: 28 Apr 2014

    Cross-site scripting (XSS) vulnerability in passwd/main.php in the Passwd module before 3.1.1 for Horde allows remote attackers to inject arbitrary web script or HTML via the backend parameter.

    Source:anonymous
    Published:8 Jul 2009
    4.3
    Medium

    CVE-2009-2352

    Last Modified: 28 Apr 2014

    Google Chrome 1.0.154.48 and earlier does not block javascript: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header or (2) specifying the content of a Refresh header, a related issue to CVE-2009-1312. NOTE: it was later reported that 2.0.172.28, 2.0.172.37, and 3.0.193.2 Beta are also affected.

    Source:MustLive
    Published:7 Jul 2009
    4.3
    Medium

    CVE-2009-2350

    Last Modified: 28 Apr 2014

    Microsoft Internet Explorer 6.0.2900.2180 and earlier does not block javascript: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header or (2) specifying the content of a Refresh header, a related issue to CVE-2009-1312.

    Source:MustLive
    Published:7 Jul 2009
    9
    Critical

    CVE-2009-2344

    Last Modified: 23 Apr 2026

    The web-based management interfaces in Sourcefire Defense Center (DC) and 3D Sensor before 4.8.2 allow remote authenticated users to gain privileges via a $admin value for the admin parameter in an edit action to admin/user/user.cgi and unspecified other components.

    Source:Gregory Duchemin
    Published:7 Jul 2009
    7.5
    High

    CVE-2009-2341

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in albumdetail.php in Opial 1.0 allows remote attackers to execute arbitrary SQL commands via the albumid parameter.

    Source:ThE g0bL!N
    Published:7 Jul 2009
    7.5
    High

    CVE-2009-2340

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin/index.php in Opial 1.0 allows remote attackers to execute arbitrary SQL commands via the txtUserName (aka User Name) parameter. NOTE: some of these details are obtained from third party information.

    Source:Moudi
    Published:7 Jul 2009
    7.5
    High

    CVE-2009-2339

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Rentventory allows remote attackers to execute arbitrary SQL commands via the product parameter.

    Source:Moudi
    Published:7 Jul 2009
    6.8
    Medium

    CVE-2009-2338

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in includes/startmodules.inc.php in FreeWebshop.org 2.2.9 R2, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang_file parameter.

    Source:ahmadbady
    Published:7 Jul 2009
    6.8
    Medium

    CVE-2009-2337

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in includes/module/book/index.inc.php in w3b|cms Gaestebuch Guestbook Module 3.0.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the spam_id parameter.

    Source:DNX
    Published:7 Jul 2009
    5
    Medium

    CVE-2009-2335

    Last Modified: 20 Aug 2011

    WordPress and WordPress MU before 2.8.1 exhibit different behavior for a failed login attempt depending on whether the user account exists, which allows remote attackers to enumerate valid usernames. NOTE: the vendor reportedly disputes the significance of this issue, indicating that the behavior exists for "user convenience."

    Source:Tiago Ferreira & Heyder Andrade
    Published:8 Jul 2009
    4.9
    Medium

    CVE-2009-2334

    Last Modified: 4 May 2017

    wp-admin/admin.php in WordPress and WordPress MU before 2.8.1 does not require administrative authentication to access the configuration of a plugin, which allows remote attackers to specify a configuration file in the page parameter to obtain sensitive information or modify this file, as demonstrated by the (1) collapsing-archives/options.txt, (2) akismet/readme.txt, (3) related-ways-to-take-action/options.php, (4) wp-security-scan/securityscan.php, and (5) wp-ids/ids-admin.php files. NOTE: this can be leveraged for cross-site scripting (XSS) and denial of service.

    Source:Core Security
    Published:8 Jul 2009
    7.5
    High

    CVE-2009-2333

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in CMS Chainuk 1.2 and earlier allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the menu parameter to admin/admin_menu.php, and the id parameter to (2) index.php and (3) admin/admin_edit.php; and (4) delete arbitrary local files via a .. (dot dot) in the id parameter to admin/admin_delete.php. NOTE: vector 2 can be leveraged for static code injection by sending a crafted menu parameter to admin/admin_menu.php, and then sending an id=../menu.csv request to index.php.

    Source:eLwaux
    Published:5 Jul 2009
    5
    Medium

    CVE-2009-2332

    Last Modified: 23 Apr 2026

    CMS Chainuk 1.2 and earlier allows remote attackers to obtain sensitive information via (1) a crafted id parameter to index.php or (2) a nonexistent folder name in the id parameter to admin/admin_delete.php, which reveals the installation path in an error message.

    Source:eLwaux
    Published:5 Jul 2009
    7.5
    High

    CVE-2009-2331

    Last Modified: 23 Apr 2026

    Multiple static code injection vulnerabilities in CMS Chainuk 1.2 and earlier allow remote attackers to inject arbitrary PHP code (1) into settings.php via the menu parameter to admin_settings.php or (2) into a content/=NUMBER.php file via the title parameter to admin_new.php.

    Source:eLwaux
    Published:5 Jul 2009
    4.3
    Medium

    CVE-2009-2330

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in admin/admin_menu.php in CMS Chainuk 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the menu parameter.

    Source:eLwaux
    Published:5 Jul 2009
    5
    Medium

    CVE-2009-2329

    Last Modified: 23 Apr 2026

    KerviNet Forum 1.1 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) admin/head.php, or (2) voting_diagram.php, (3) voting.php, (4) topics_search.php, (5) topics_list.php, (6) top_part.php, (7) quick_search.php, (8) quick_reply.php, (9) moder_menu.php, (10) messages_list.php, (11) menu.php, (12) head.php, (13) forums_list.php, (14) forum_statistics.php, (15) forum_info.php, or (16) birthday.php in include_files/, which reveals the installation path in an error message.

    Source:eLwaux
    Published:5 Jul 2009
    7.5
    High

    CVE-2009-2328

    Last Modified: 23 Apr 2026

    admin/edit_user.php in KerviNet Forum 1.1 and earlier does not require administrative authentication, which allows remote attackers to delete arbitrary accounts and conduct SQL injection attacks via the del_user_id parameter.

    Source:eLwaux
    Published:5 Jul 2009
    3.5
    Low

    CVE-2009-2327

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in add_voting.php in KerviNet Forum 1.1 and earlier allows remote authenticated users to inject arbitrary web script or HTML via the v_variant1 parameter.

    Source:eLwaux
    Published:5 Jul 2009
    7.5
    High

    CVE-2009-2326

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in KerviNet Forum 1.1 and earlier allow remote attackers to execute arbitrary SQL commands via (1) an enter_parol cookie to index.php in an auto action or (2) the topic parameter to message.php. NOTE: vector 2 can be leveraged for a cross-site scripting (XSS) attack.

    Source:eLwaux
    Published:5 Jul 2009
    5
    Medium

    CVE-2009-2325

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in Clicknet CMS 2.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the side parameter.

    Source:ThE g0bL!N
    Published:5 Jul 2009
    7.5
    High

    CVE-2009-2313

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in Jinzora Media Jukebox 2.8 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the name parameter.

    Source:dun
    Published:2 Jul 2009
    7.5
    High

    CVE-2009-2311

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the rGallery plugin 1.2.3 for WoltLab Burning Board (WBB3) allows remote attackers to execute arbitrary SQL commands via the userID parameter in the RGalleryUserGallery page to index.php, a different vector than CVE-2008-4627.

    Source:Invisibility
    Published:2 Jul 2009
    7.5
    High

    CVE-2009-2310

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in include/get_read.php in Extensible-BioLawCom CMS (X-BLC) 0.2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the section parameter.

    Source:dun
    Published:2 Jul 2009
    7.5
    High

    CVE-2009-2309

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Codice CMS 2 allows remote attackers to execute arbitrary SQL commands via the tag parameter.

    Source:darkjoker
    Published:2 Jul 2009
    7.5
    High

    CVE-2009-2308

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in affiliates.php in the Affiliation (aka Affiliates) module 1.1.0 and earlier for PunBB allow remote attackers to execute arbitrary SQL commands via the (1) in or (2) out parameter.

    Source:Dante90
    Published:2 Jul 2009
    7.5
    High

    CVE-2009-2307

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the CWGuestBook module 2.1 and earlier for MAXdev MDPro (aka MD-Pro) allows remote attackers to execute arbitrary SQL commands via the rid parameter in a viewrecords action to modules.php.

    Source:Dante90
    Published:2 Jul 2009
    7.5
    High

    CVE-2009-2306

    Last Modified: 23 Apr 2026

    The ARD-9808 DVR card security camera stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a file containing usernames and passwords via a direct request for dvr.ini.

    Source:Septemb0x
    Published:2 Jul 2009
    7.8
    High

    CVE-2009-2305

    Last Modified: 29 Sept 2016

    The ARD-9808 DVR card security camera allows remote attackers to cause a denial of service via a long URI composed of //.\ (slash slash dot backslash) sequences.

    Source:Stack
    Published:2 Jul 2009
    4.3
    Medium

    CVE-2009-2302

    Last Modified: 28 Apr 2014

    Cross-site scripting (XSS) vulnerability in index.php in Aardvark Topsites PHP 5.2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the q parameter in a search action. NOTE: it was later reported that 5.2.1 is also affected.

    Source:anonymous
    Published:2 Jul 2009
    7.5
    High

    CVE-2009-2293

    Last Modified: 23 Apr 2026

    Optimum Web Design Tutorial Share 3.5.0 and earlier allows remote attackers to bypass authentication and obtain administrative access by setting the usernamed cookie parameter.

    Source:Evil-Cod3r
    Published:1 Jul 2009
    7.5
    High

    CVE-2009-2290

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Boy Scout Advancement (com_bsadv) component 0.3 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a (1) account or (2) event task to index.php.

    Source:YEnH4ckEr
    Published:1 Jul 2009
    4.3
    Medium

    CVE-2009-2289

    Last Modified: 12 Oct 2014

    Cross-site scripting (XSS) vulnerability in index.php in Arcade Trade Script 1.0 beta allows remote attackers to inject arbitrary web script or HTML via the q parameter in a gamelist action.

    Source:SmOk3
    Published:1 Jul 2009
    7.5
    High

    CVE-2009-2288

    Last Modified: 27 Apr 2014

    statuswml.cgi in Nagios before 3.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) ping or (2) Traceroute parameters.

    Source:Paul
    Published:18 Jun 2009
    4.3
    Medium

    CVE-2009-2286

    Last Modified: 27 Oct 2016

    Buffer overflow in compface 1.5.2 and earlier allows user-assisted attackers to cause a denial of service (crash) via a long declaration in a .xbm file. NOTE: this issue only affects compface on distributions that used a certain patch.

    Source:metalhoney
    Published:1 Jul 2009
    4.3
    Medium

    CVE-2009-2285

    Last Modified: 27 Apr 2014

    Buffer underflow in the LZWDecodeCompat function in libtiff 3.8.2 allows context-dependent attackers to cause a denial of service (crash) via a crafted TIFF image, a different vulnerability than CVE-2008-2327.

    Source:wololo
    Published:3 Jan 2009
    7.5
    High

    CVE-2009-2276

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in voteforus.php in the Vote For Us extension 1.0.1 and earlier for PunBB allows remote attackers to execute arbitrary SQL commands via the out parameter.

    Source:Dante90
    Published:1 Jul 2009
    5
    Medium

    CVE-2009-2275

    Last Modified: 30 Dec 2016

    Directory traversal vulnerability in frontend/x3/stats/lastvisit.html in cPanel allows remote attackers to read arbitrary files via a .. (dot dot) in the domain parameter.

    Source:SecurityRules
    Published:1 Jul 2009
    7.5
    High

    CVE-2009-2269

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Empire CMS 5.1 allows remote attackers to execute arbitrary SQL commands via the bid parameter to the default URI under e/tool/gbook/.

    Source:Securitylab Security Research
    Published:1 Jul 2009
    6.9
    Medium

    CVE-2009-2267

    Last Modified: 14 Jul 2017

    VMware Workstation 6.5.x before 6.5.3 build 185404, VMware Player 2.5.x before 2.5.3 build 185404, VMware ACE 2.5.x before 2.5.3 build 185404, VMware Server 1.x before 1.0.10 build 203137 and 2.x before 2.0.2 build 203138, VMware Fusion 2.x before 2.0.6 build 196839, VMware ESXi 3.5 and 4.0, and VMware ESX 2.5.5, 3.0.3, 3.5, and 4.0, when Virtual-8086 mode is used, do not properly set the exception code upon a page fault (aka #PF) exception, which allows guest OS users to gain privileges on the guest OS by specifying a crafted value for the cs register.

    Source:Tavis Ormandy & Julien Tinnes
    Published:2 Nov 2009