6.4
    Medium

    CVE-2009-1665

    Last Modified: 23 Apr 2026

    myaccount.php in Easy Scripts Answer and Question Script allows remote attackers to remove arbitrary user accounts via a modified userid parameter without specifying any additional fields.

    Source:InjEctOr5
    Published:17 May 2009
    7.5
    High

    CVE-2009-1664

    Last Modified: 23 Apr 2026

    myaccount.php in Easy Scripts Answer and Question Script does not verify the original password before changing passwords, which allows remote attackers to change the password of other users and gain privileges via modified userid, txtpassword, and txtRpassword parameters.

    Source:InjEctOr5
    Published:17 May 2009
    6.8
    Medium

    CVE-2009-1663

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in myaccount.php in Easy Scripts Answer and Question Script allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in the uploads/[username] directory.

    Source:InjEctOr5
    Published:17 May 2009
    7.5
    High

    CVE-2009-1662

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in admin/login.php in Wright Way Services Recipe Script 5 allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) Password fields, as reachable from admin/index.php.

    Source:TiGeR-Dz
    Published:17 May 2009
    6.8
    Medium

    CVE-2009-1661

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin/utopic.php in uTopic 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the rating parameter to index.php.

    Source:YEnH4ckEr
    Published:17 May 2009
    9.3
    Critical

    CVE-2009-1660

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in URUWorks ViPlay3 3.0 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long file entry in a .vpl file.

    Source:LiquidWorm
    Published:17 May 2009
    6.8
    Medium

    CVE-2009-1659

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in admin/uploadimage.php in eLitius 1.0 allows remote attackers to bypass intended access restrictions and upload and execute arbitrary files via an avatar file with an accepted Content-Type such as image/gif, then requesting the file in admin/banners/.

    Source:G4N0K
    Published:17 May 2009
    7.5
    High

    CVE-2009-1658

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in admin/admin.php in Realty Webware Technologies Realty Web-Base 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) user (username) and (2) password parameters. NOTE: some of these details are obtained from third party information.

    Source:ThE g0bL!N
    Published:17 May 2009
    6.5
    Medium

    CVE-2009-1655

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in myaccount.php in Easy Scripts Answer and Question Script allow remote authenticated users to execute arbitrary SQL commands via the (1) user name (userid parameter) and (2) password.

    Source:InjEctOr5
    Published:16 May 2009
    4.3
    Medium

    CVE-2009-1654

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in questiondetail.php in Easy Scripts Answer and Question Script allows remote attackers to inject arbitrary web script or HTML via the questionid parameter.

    Source:InjEctOr5
    Published:16 May 2009
    7.8
    High

    CVE-2009-1653

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in examples/tbs_us_examples_0view.php in TinyButStrong 3.4.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the script parameter.

    Source:ahmadbady
    Published:16 May 2009
    7.5
    High

    CVE-2009-1652

    Last Modified: 23 Apr 2026

    admin/adminaddeditdetails.php in Business Community Script does not properly restrict access, which allows remote attackers to gain privileges and add administrators via a direct request.

    Source:TiGeR-Dz
    Published:16 May 2009
    7.5
    High

    CVE-2009-1651

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin/member_details.php in 2daybiz Business Community Script allows remote attackers to execute arbitrary SQL commands via the mid parameter.

    Source:TiGeR-Dz
    Published:16 May 2009
    7.5
    High

    CVE-2009-1650

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in photos.php in Shutter 0.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) albumID, (2) tagID, and (3) photoID parameters to index.html.

    Source:YEnH4ckEr
    Published:16 May 2009
    7.5
    High

    CVE-2009-1649

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in arch.php in beLive 0.2.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the arch parameter.

    Source:Kacper
    Published:16 May 2009
    9.3
    Critical

    CVE-2009-1647

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in popcorn.exe in Ultrafunk Popcorn 1.87 allows remote POP3 servers to cause a denial of service (application crash) via a long string in a +OK response. NOTE: some of these details are obtained from third party information.

    Source:x.CJP.x
    Published:15 May 2009
    9.3
    Critical

    CVE-2009-1646

    Last Modified: 26 Mar 2015

    Stack-based buffer overflow in Mini-stream RM Downloader 3.0.0.9 allows remote attackers to execute arbitrary code via a long rtsp URL in a .ram file.

    Source:TUNISIAN CYBER
    Published:15 May 2009
    9.3
    Critical

    CVE-2009-1645

    Last Modified: 22 Dec 2017

    Multiple stack-based buffer overflows in Mini-stream Easy RM-MP3 Converter 3.0.0.7 allow remote attackers to execute arbitrary code via (1) a long rtsp URL in a .ram file and (2) a long string in the HREF attribute of a REF element in a .asx file.

    Source:G4N0K
    Published:15 May 2009
    9.3
    Critical

    CVE-2009-1644

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Sorinara Streaming Audio Player 0.9 allows remote attackers to execute arbitrary code via a crafted .pla file.

    Source:GoLd_M
    Published:15 May 2009
    9.3
    Critical

    CVE-2009-1643

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Sorinara Soritong MP3 Player 1.0 allows remote attackers to execute arbitrary code via a crafted .m3u file.

    Source:hack4love
    Published:15 May 2009
    9.3
    Critical

    CVE-2009-1642

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in Mini-stream ASX to MP3 Converter 3.0.0.7 allow remote attackers to execute arbitrary code via (1) a long rtsp URL in a .ram file and (2) a long string in the HREF attribute of a REF element in a .asx file. NOTE: the latter was also subsequently reported in "prior to 3.1.3.7."

    Source:mat
    Published:15 May 2009
    9.3
    Critical

    CVE-2009-1641

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in Mini-stream Ripper 3.0.1.1 allow remote attackers to execute arbitrary code via (1) a long rtsp URL in a .ram file and (2) a long string in the HREF attribute of a REF element in a .asx file.

    Source:G4N0K
    Published:15 May 2009
    7.5
    High

    CVE-2009-1638

    Last Modified: 23 Apr 2026

    Techno Dreams Job Career Package 3.0 allows remote attackers to bypass authentication and obtain administrative access by setting the JobCareerAdmin cookie to Login.

    Source:TiGeR-Dz
    Published:15 May 2009
    6.4
    Medium

    CVE-2009-1637

    Last Modified: 23 Apr 2026

    profile.php in Simple Customer 1.3 does not require administrative authentication, which allows remote attackers to change the admin e-mail address and password via the email and password parameters.

    Source:ahmadbady
    Published:15 May 2009
    7.5
    High

    CVE-2009-1634

    Last Modified: 18 Dec 2016

    The WebAccess component in Novell GroupWise 7.x before 7.03 HP3 and 8.x before 8.0 HP2 does not properly implement session management mechanisms, which allows remote attackers to gain access to user accounts via unspecified vectors.

    Source:Gregory Duchemin
    Published:26 May 2009
    9.3
    Critical

    CVE-2009-1627

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Streaming Download Project (SDP) Downloader 2.3.0 allows remote attackers to execute arbitrary code via a long .asf URL in the HREF attribute of a REF element in a .asx file.

    Source:Cyber-Zone
    Published:12 May 2009
    7.5
    High

    CVE-2009-1626

    Last Modified: 17 Feb 2017

    SQL injection vulnerability in public/specific.php in EZ-Blog before Beta 2 20090427, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the category parameter.

    Source:YEnH4ckEr
    Published:12 May 2009
    6.8
    Medium

    CVE-2009-1625

    Last Modified: 20 Dec 2016

    Directory traversal vulnerability in index.php in Thickbox Gallery 2 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the ln parameter.

    Source:SirGod
    Published:12 May 2009
    5
    Medium

    CVE-2009-1624

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in Dew-NewPHPLinks 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the show parameter.

    Source:d3v1l
    Published:12 May 2009
    4.3
    Medium

    CVE-2009-1623

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Dew-NewPHPLinks 2.0 allows remote attackers to inject arbitrary web script or HTML via the PID parameter.

    Source:d3v1l
    Published:12 May 2009
    7.5
    High

    CVE-2009-1622

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in user.php in EcShop 2.5.0 allows remote attackers to execute arbitrary SQL commands via the order_sn parameter in an order_query action.

    Source:Securitylab.ir
    Published:12 May 2009
    5
    Medium

    CVE-2009-1621

    Last Modified: 22 Nov 2016

    Directory traversal vulnerability in index.php in OpenCart 1.1.8 allows remote attackers to read arbitrary files via a .. (dot dot) in the route parameter.

    Source:OoN_Boy
    Published:12 May 2009
    4.3
    Medium

    CVE-2009-1620

    Last Modified: 21 Apr 2014

    Multiple cross-site scripting (XSS) vulnerabilities in input.php in MataChat allow remote attackers to inject arbitrary web script or HTML via the (1) nickname and (2) color parameters.

    Source:Am!r
    Published:12 May 2009
    7.5
    High

    CVE-2009-1619

    Last Modified: 23 Apr 2026

    Teraway FileStream 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the twFSadmin cookie to 1.

    Source:ThE g0bL!N
    Published:12 May 2009
    7.5
    High

    CVE-2009-1618

    Last Modified: 23 Apr 2026

    Teraway LiveHelp 2.0 allows remote attackers to bypass authentication and gain administrative access via a pwd=&lvl=1&usr=&alias=admin&userid=1 value for the TWLHadmin cookie.

    Source:ThE g0bL!N
    Published:12 May 2009
    7.5
    High

    CVE-2009-1617

    Last Modified: 23 Apr 2026

    Teraway LinkTracker 1.0 allows remote attackers to bypass authentication and gain administrative access via a userid=1&lvl=1 value for the twLTadmin cookie.

    Source:ThE g0bL!N
    Published:12 May 2009
    4.3
    Medium

    CVE-2009-1616

    Last Modified: 21 Dec 2016

    Cross-site scripting (XSS) vulnerability in docs/showdoc.php in Coppermine Photo Gallery (CPG) before 1.4.22 allows remote attackers to inject arbitrary web script or HTML via the css parameter, a different vector than CVE-2008-0505.

    Source:Gerendi Sandor Attila
    Published:11 May 2009
    6.8
    Medium

    CVE-2009-1615

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in Leap CMS 0.1.4 allows remote attackers to execute arbitrary code by uploading a file with an executable extension via an admin.system.files (aka Manage Files) request to the default URI, then accessing the file via a direct request.

    Source:YEnH4ckEr
    Published:11 May 2009
    2.6
    Low

    CVE-2009-1614

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Leap CMS 0.1.4 allow remote attackers to inject arbitrary web script or HTML via (1) the msg parameter (aka the message in an article comment) or (2) the searchterm parameter (aka the search post form). NOTE: some of these details are obtained from third party information.

    Source:YEnH4ckEr
    Published:11 May 2009
    6.8
    Medium

    CVE-2009-1613

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in leap.php in Leap CMS 0.1.4, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) searchterm or (2) email parameter.

    Source:YEnH4ckEr
    Published:11 May 2009
    9.3
    Critical

    CVE-2009-1612

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the MPS.StormPlayer.1 ActiveX control in mps.dll 3.9.4.27 in Baofeng Storm allows remote attackers to execute arbitrary code via a long argument to the OnBeforeVideoDownload method, as exploited in the wild in April and May 2009. NOTE: some of these details are obtained from third party information. NOTE: it was later reported that 3.09.04.17 and earlier are also affected.

    Source:MITBOY
    Published:11 May 2009
    10
    Critical

    CVE-2009-1611

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in ElectraSoft 32bit FTP 09.04.24 allows remote FTP servers to execute arbitrary code via a long 257 reply to a CWD command.

    Source:His0k4
    Published:11 May 2009
    7.5
    High

    CVE-2009-1610

    Last Modified: 23 Apr 2026

    admin/changepassword.php in Job Script Job Board Software 2.0 allows remote attackers to change the administrator password and gain administrator privileges via a direct request.

    Source:TiGeR-Dz
    Published:11 May 2009
    6.8
    Medium

    CVE-2009-1609

    Last Modified: 5 Dec 2016

    Unrestricted file upload vulnerability in admin/uploadform.asp in Battle Blog 1.25 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file.

    Source:Cyber-Zone
    Published:11 May 2009
    9.3
    Critical

    CVE-2009-1608

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in Microchip MPLAB IDE 8.30 and possibly earlier versions allow user-assisted remote attackers to execute arbitrary code via a .MCP project file with long (1) FILE_INFO, (2) CAT_FILTERS, and possibly other fields.

    Source:His0k4
    Published:11 May 2009
    4.3
    Medium

    CVE-2009-1607

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the administrator panel in phpForm.net LinkBase 2.0 allows remote attackers to inject arbitrary web script or HTML via the username in a registration, which is not properly handled when the administrator accesses the Users menu.

    Source:SirGod
    Published:11 May 2009
    5
    Medium

    CVE-2009-1602

    Last Modified: 23 Apr 2026

    Pablo Software Solutions Quick 'n Easy Mail Server 3.3 allows remote attackers to cause a denial of service (daemon outage or CPU consumption) via multiple long SMTP commands, as demonstrated by HELO commands.

    Source:shinnai
    Published:11 May 2009
    4
    Medium

    CVE-2009-1595

    Last Modified: 22 Apr 2014

    The jabber:iq:auth implementation in IQAuthHandler.java in Ignite Realtime Openfire before 3.6.4 allows remote authenticated users to change the passwords of arbitrary accounts via a modified username element in a passwd_change action.

    Source:Daryl Herzmann
    Published:11 May 2009
    4.3
    Medium

    CVE-2009-1593

    Last Modified: 24 Apr 2014

    Armorlogic Profense Web Application Firewall before 2.2.22, and 2.4.x before 2.4.4, does not properly implement the "negative model," which allows remote attackers to conduct cross-site scripting (XSS) attacks via a modified end tag of a SCRIPT element.

    Source:EnableSecurity
    Published:21 May 2009
    10
    Critical

    CVE-2009-1592

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in ElectraSoft 32bit FTP 09.04.24 allows remote FTP servers to execute arbitrary code via a long banner. NOTE: this might overlap CVE-2003-1368.

    Source:Load 99%
    Published:8 May 2009