6.4
    Medium

    CVE-2009-2159

    Last Modified: 2 Jan 2017

    backup-database.php in TorrentTrader Classic 1.09 does not require administrative authentication, which allows remote attackers to create and download a backup database by making a direct request and then retrieving a .gz file from backups/.

    Source:waraxe
    Published:22 Jun 2009
    7.5
    High

    CVE-2009-2158

    Last Modified: 2 Jan 2017

    account-recover.php in TorrentTrader Classic 1.09 chooses random passwords from an insufficiently large set, which makes it easier for remote attackers to obtain a password via a brute-force attack.

    Source:waraxe
    Published:22 Jun 2009
    6.5
    Medium

    CVE-2009-2157

    Last Modified: 2 Jan 2017

    Multiple SQL injection vulnerabilities in TorrentTrader Classic 1.09 allow remote authenticated users to execute arbitrary SQL commands via (1) the origmsg parameter to account-inbox.php; the categ parameter to (2) delreq.php and (3) admin-delreq.php; (4) the choice parameter to index.php; (5) the id parameter to modrules.php in an edited (aka edit) action; the (6) user, (7) torrent, (8) forumid, and (9) forumpost parameters to report.php; (10) the delmp parameter to take-deletepm.php; (11) the delreport parameter to takedelreport.php; (12) the delreq parameter to takedelreq.php; (13) the clases parameter to takestaffmess.php; and (14) the warndisable parameter to takewarndisable.php; and allow remote attackers to execute arbitrary SQL commands via (15) the wherecatin parameter to browse.php, (16) the limit parameter to today.php, and (17) the where parameter to torrents-details.php.

    Source:waraxe
    Published:22 Jun 2009
    3.5
    Low

    CVE-2009-2156

    Last Modified: 2 Jan 2017

    Multiple cross-site scripting (XSS) vulnerabilities in TorrentTrader Classic 1.09 allow remote authenticated users to inject arbitrary web script or HTML via (1) the Title field to requests.php, related to viewrequests.php; and (2) the Torrent Name field to torrents-upload.php, related to the logging of torrent uploads; and allow remote attackers to inject arbitrary web script or HTML via (3) the ttversion parameter to themes/default/footer.php, the (4) SITENAME and (5) CURUSER[username] parameters to themes/default/header.php, (6) the todayactive parameter to visitorstoday.php, (7) the activepeople parameter to visitorsnow.php, (8) the faq_categ[999][title] parameter to faq.php, and (9) the keepget parameter to torrents-details.php.

    Source:waraxe
    Published:22 Jun 2009
    6.8
    Medium

    CVE-2009-2154

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin/login.php in Impleo Music Collection 2.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the username parameter.

    Source:SirGod
    Published:22 Jun 2009
    4.3
    Medium

    CVE-2009-2153

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Impleo Music Collection 2.0 allows remote attackers to inject arbitrary web script or HTML via the sort parameter.

    Source:SirGod
    Published:22 Jun 2009
    7.5
    High

    CVE-2009-2152

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in a_index.php in AdaptWeb 0.9.2 allows remote attackers to execute arbitrary SQL commands via the CodigoDisciplina parameter in a TopicosCadastro1 action.

    Source:SirGod
    Published:22 Jun 2009
    5
    Medium

    CVE-2009-2151

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in AdaptWeb 0.9.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the newlang parameter.

    Source:SirGod
    Published:22 Jun 2009
    6.8
    Medium

    CVE-2009-2150

    Last Modified: 23 Apr 2026

    Multiple cross-site request forgery (CSRF) vulnerabilities in Campus Virtual-LMS allow (1) remote attackers to hijack the authentication of arbitrary users for requests that terminate a session via login/logout.php, and might allow remote attackers to hijack the authentication of certain users via a (2) ADD or (3) DELETE action to enrolments/step2.php.

    Source:Yasión
    Published:22 Jun 2009
    4.3
    Medium

    CVE-2009-2149

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Campus Virtual-LMS allow remote attackers to inject arbitrary web script or HTML via the (1) courseid parameter to enrolments/step1.php, or the (2) search or (3) siteid parameter to files/shared_list.php.

    Source:Yasión
    Published:22 Jun 2009
    7.5
    High

    CVE-2009-2148

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in news/index.php in Campus Virtual-LMS allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Yasión
    Published:22 Jun 2009
    7.5
    High

    CVE-2009-2147

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in fdown.php in phpWebThings 1.5.2 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:StAkeR
    Published:22 Jun 2009
    6
    Medium

    CVE-2009-2146

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in the Compose Email feature in the Emails module in Sugar Community Edition (aka SugarCRM) before 5.2f allows remote authenticated users to execute arbitrary code by uploading a file with only an extension in its name, then accessing the file via a direct request to a modified filename under cache/modules/Emails/, as demonstrated using .php as the entire original name.

    Source:USH
    Published:22 Jun 2009
    4.3
    Medium

    CVE-2009-2145

    Last Modified: 21 Dec 2016

    Multiple cross-site scripting (XSS) vulnerabilities in transLucid 1.75 allow remote attackers to inject arbitrary web script or HTML via the (a) NodeID and (b) action parameters to the default URI, and the (c) NodeID parameter to the default URI for the admin section; and allow remote authenticated users to inject arbitrary web script or HTML via the (d) Title (aka page name) and (e) Url fields in a (1) new or (2) modified page.

    Source:intern0t
    Published:22 Jun 2009
    7.5
    High

    CVE-2009-2142

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in admin/index.asp in Zip Store Chat 4.0 and 5.0 allow remote attackers to execute arbitrary SQL commands via the (1) login and (2) senha parameters.

    Source:ByALBAYX
    Published:22 Jun 2009
    4.3
    Medium

    CVE-2009-2141

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in TBDev.NET 01-01-08 allow remote attackers to inject arbitrary web script or HTML via (1) the returnto parameter to makepoll.php, (2) the returnto parameter in a delete action to polls.php, or the (3) Info or (4) Avatar field to my.php.

    Source:intern0t
    Published:22 Jun 2009
    4.3
    Medium

    CVE-2009-2138

    Last Modified: 23 Apr 2026

    Multiple open redirect vulnerabilities in TBDev.NET 01-01-08 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via (1) the returnto parameter to login.php or (2) the returnto parameter in a delete action to news.php. NOTE: this can be leveraged for cross-site scripting (XSS) by redirecting to a data: URI.

    Source:intern0t
    Published:19 Jun 2009
    5
    Medium

    CVE-2009-2134

    Last Modified: 23 Apr 2026

    pivot/tb.php in Pivot 1.40.4 and 1.40.7 allows remote attackers to obtain sensitive information via an invalid url parameter, which reveals the installation path in an error message.

    Source:intern0t
    Published:19 Jun 2009
    4.3
    Medium

    CVE-2009-2133

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Pivot 1.40.4 and 1.40.7 allow remote attackers to inject arbitrary web script or HTML via the (1) menu or (2) sort parameter to pivot/index.php, (3) the value of a check array parameter in a delete action to pivot/index.php, (4) the element name in a check array parameter in a delete action to pivot/index.php, (5) the edituser parameter in an edituser action to pivot/index.php, (6) the edit parameter in a templates action to pivot/index.php, (7) the blog parameter in a blog_edit1 action to pivot/index.php, (8) the cat parameter in a cat_edit action to pivot/index.php, (9) a certain form field in a doaction=1 request to pivot/index.php, (10) the url field in a my_weblog edit_prefs action to pivot/user.php, or (11) the username (aka name) field in a my_weblog reg_user action to pivot/user.php.

    Source:intern0t
    Published:19 Jun 2009
    6.8
    Medium

    CVE-2009-2132

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in global.php in 4images before 1.7.7, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the l parameter.

    Source:Qabandi
    Published:19 Jun 2009
    3.5
    Low

    CVE-2009-2131

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in 4images 1.7.7 and earlier allows remote authenticated users to inject arbitrary web script or HTML by providing a crafted user_homepage parameter to member.php, and then posting a comment associated with a picture.

    Source:Qabandi
    Published:19 Jun 2009
    5
    Medium

    CVE-2009-2130

    Last Modified: 23 Apr 2026

    Elvin 1.2.0 allows remote attackers to read the PHP source code of (1) login.ei, (2) jump_bug.ei, or (3) create_account.ei in inc/ via a direct request.

    Source:SirGod
    Published:19 Jun 2009
    6.8
    Medium

    CVE-2009-2129

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in login.php in Elvin 1.2.0 allows remote attackers to hijack the authentication of arbitrary users via a logout action.

    Source:SirGod
    Published:19 Jun 2009
    4.3
    Medium

    CVE-2009-2127

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in show_activity.php in Elvin 1.2.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter.

    Source:SirGod
    Published:19 Jun 2009
    7.5
    High

    CVE-2009-2124

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in page.php in Elvin 1.2.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the id parameter.

    Source:SirGod
    Published:19 Jun 2009
    7.5
    High

    CVE-2009-2123

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Elvin 1.2.0 allow remote attackers to execute arbitrary SQL commands via the (1) inUser (aka Username) and (2) inPass (aka Password) parameters to (a) inc/login.ei, reachable through login.php; and the (3) id parameter to (b) show_bug.php and (c) show_activity.php. NOTE: it was later reported that vector 3c also affects 1.2.2.

    Source:SirGod
    Published:19 Jun 2009
    7.5
    High

    CVE-2009-2122

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in viewimg.php in the Paolo Palmonari Photoracer plugin 1.0 for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Kacper
    Published:19 Jun 2009
    6.5
    Medium

    CVE-2009-2120

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in TekBase All-in-One 3.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) ids parameter to admin.php, the (2) y parameter to members.php, and other unspecified vectors. NOTE: vector 1 requires administrative access.

    Source:n3wb0ss
    Published:18 Jun 2009
    7.5
    High

    CVE-2009-2117

    Last Modified: 13 Dec 2016

    uye_paneli.php in phPortal 1.0 allows remote attackers to bypass authentication and obtain administrative access by setting the kulladi cookie to a valid username.

    Source:KnocKout
    Published:18 Jun 2009
    4
    Medium

    CVE-2009-2116

    Last Modified: 7 Oct 2014

    Directory traversal vulnerability in admin.php in SkyBlueCanvas 1.1 r237 allows remote authenticated administrators to list directory contents via a .. (dot dot) in the dir parameter.

    Source:MaXe
    Published:18 Jun 2009
    4.3
    Medium

    CVE-2009-2114

    Last Modified: 3 Oct 2014

    Multiple cross-site scripting (XSS) vulnerabilities in admin.php in SkyBlueCanvas 1.1 r237 allow remote attackers to inject arbitrary web script or HTML via the (1) mgroup, (2) mgr, (3) objtype, (4) id, and (5) dir parameters.

    Source:MaXe
    Published:18 Jun 2009
    7.5
    High

    CVE-2009-2113

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in FretsWeb 1.2 allow remote attackers to execute arbitrary SQL commands via the (1) name parameter to player.php and the (2) hash parameter to song.php.

    Source:YEnH4ckEr
    Published:18 Jun 2009
    7.5
    High

    CVE-2009-2112

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in include/page_bottom.php in phpFK 7.03 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the _FORUM[settings_design_style] parameter.

    Source:ahmadbady
    Published:18 Jun 2009
    10
    Critical

    CVE-2009-2111

    Last Modified: 23 Apr 2026

    Static code injection vulnerability in add_reg.php in DB Top Sites 1.0 allows remote attackers to inject arbitrary PHP code via a crafted (1) url and (2) location parameter.

    Source:SirGod
    Published:18 Jun 2009
    7.6
    High

    CVE-2009-2110

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in DB Top Sites 1.0, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the u parameter to (1) full.php, (2) index.php, and (3) contact.php.

    Source:SirGod
    Published:18 Jun 2009
    5
    Medium

    CVE-2009-2109

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in FretsWeb 1.2 allow remote attackers to read arbitrary files via directory traversal sequences in the (1) language parameter to charts.php and the (2) fretsweb_language cookie parameter to unspecified vectors, possibly related to admin/common.php.

    Source:YEnH4ckEr
    Published:18 Jun 2009
    5
    Medium

    CVE-2009-2108

    Last Modified: 26 Apr 2014

    git-daemon in git 1.4.4.5 through 1.6.3 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a request containing extra unrecognized arguments.

    Source:Shawn O. Pearce
    Published:18 Jun 2009
    4.3
    Medium

    CVE-2009-2107

    Last Modified: 26 Apr 2014

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in Webmedia Explorer (webmex) 5.09 and 5.10 allow remote attackers to inject arbitrary web script or HTML via event handlers such as onmouseover in the (1) search or (2) tag parameters; (3) arbitrary invalid parameter names that are not properly handled when triggered on a column; (4) bookmark parameter in an edit action; or (5) email parameter in a remember action.

    Source:intern0t
    Published:17 Jun 2009
    7.5
    High

    CVE-2009-2102

    Last Modified: 5 Mar 2017

    SQL injection vulnerability in the Jumi (com_jumi) component 2.0.3 and possibly other versions for Joomla allows remote attackers to execute arbitrary SQL commands via the fileid parameter to index.php.

    Source:Chip d3 bi0s
    Published:17 Jun 2009
    6.8
    Medium

    CVE-2009-2101

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in archive.php in TorrentVolve 1.4, when register_globals is enabled, allows remote attackers to delete arbitrary files via a .. (dot dot) in the deleteTorrent parameter.

    Source:Br0ly
    Published:17 Jun 2009
    5
    Medium

    CVE-2009-2100

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the JoomlaPraise Projectfork (com_projectfork) component 2.0.10 for Joomla! allows remote attackers to read arbitrary files via directory traversal sequences in the section parameter to index.php.

    Source:ByALBAYX
    Published:17 Jun 2009
    7.5
    High

    CVE-2009-2099

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the iJoomla RSS Feeder (com_ijoomla_rss) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cat parameter in an xml action to index.php.

    Source:Mehmet Ince
    Published:17 Jun 2009
    7.5
    High

    CVE-2009-2098

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in topicler.php in phPortal 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Mehmet Ince
    Published:17 Jun 2009
    7.5
    High

    CVE-2009-2096

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in house/listing_view.php in phpCollegeExchange 0.1.5c allows remote attackers to execute arbitrary SQL commands via the itemnr parameter.

    Source:SirGod
    Published:17 Jun 2009
    6.8
    Medium

    CVE-2009-2095

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in template/simpledefault/admin/_masterlayout.php in Mundi Mail 0.8.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the top parameter. NOTE: when allow_url_fopen is disabled, directory traversal attacks are possible to include and execute arbitrary local files.

    Source:Br0ly
    Published:17 Jun 2009
    4.3
    Medium

    CVE-2009-2081

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in help.php in phpWebThings 1.5.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the module parameter.

    Source:Br0ly
    Published:16 Jun 2009
    7.5
    High

    CVE-2009-2080

    Last Modified: 23 Apr 2026

    admin.php in MRCGIGUY The Ticket System 2.0 does not properly restrict access, which allows remote attackers to (1) obtain sensitive configuration information via the editconfig action or (2) change the administrator's password via the id parameter in an editop action.

    Source:ThE g0bL!N
    Published:16 Jun 2009
    4.3
    Medium

    CVE-2009-2044

    Last Modified: 26 Apr 2014

    Mozilla Firefox 3.0.10 and earlier on Linux allows remote attackers to cause a denial of service (application crash) via a URI for a large GIF image in the BACKGROUND attribute of a BODY element.

    Source:Ahmad Muammar
    Published:12 Jun 2009
    4.3
    Medium

    CVE-2009-2043

    Last Modified: 27 Apr 2014

    nsViewManager.cpp in Mozilla Firefox 3.0.2 through 3.0.10 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors related to interaction with TinyMCE.

    Source:Bret McMillan
    Published:12 Jun 2009
    7.5
    High

    CVE-2009-2040

    Last Modified: 23 Apr 2026

    admin/options.php in Grestul 1.2 does not properly restrict access, which allows remote attackers to bypass authentication and create administrative accounts via a manage_admin action in a direct request.

    Source:ThE g0bL!N
    Published:12 Jun 2009