7.5
    High

    CVE-2009-1587

    Last Modified: 23 Apr 2026

    index.php in PHP Site Lock 2.0 allows remote attackers to bypass authentication and obtain administrative access by setting the login_id, group_id, login_name, user_id, and user_type cookies to certain values.

    Source:ThE g0bL!N
    Published:7 May 2009
    9.3
    Critical

    CVE-2009-1586

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the NZB importer feature in GrabIt 1.7.2 Beta 3 and earlier allows remote attackers to execute arbitrary code via a crafted DTD reference in a DOCTYPE element in an NZB file.

    Source:Gaurav Baruah
    Published:7 May 2009
    4.4
    Medium

    CVE-2009-1585

    Last Modified: 27 Oct 2016

    Multiple SQL injection vulnerabilities in TemaTres 1.031, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) id_correo_electronico and (2) id_password parameters to login.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:YEnH4ckEr
    Published:7 May 2009
    6
    Medium

    CVE-2009-1584

    Last Modified: 27 Oct 2016

    Multiple SQL injection vulnerabilities in TemaTres 1.0.3 and 1.031, when magic_quotes_gpc is disabled, allow remote attackers or remote authenticated users to execute arbitrary SQL commands via the (1) mail, (2) password, and (3) letra parameters to index.php; (4) y and (5) m parameters to sobre.php; and the (6) dcTema, (7) madsTema, (8) zthesTema, (9) skosTema, and (10) xtmTema parameters to xml.php.

    Source:YEnH4ckEr
    Published:7 May 2009
    4.3
    Medium

    CVE-2009-1583

    Last Modified: 27 Oct 2016

    Multiple cross-site scripting (XSS) vulnerabilities in TemaTres 1.0.3 and 1.031 allow remote attackers to inject arbitrary web script or HTML via the (1) search form; (2) _expresion_de_busqueda, (3) letra, (4) estado_id, and (5) tema parameters to index.php; the (6) PATH_INFO to index.php; (7) unspecified parameters when editing a term as specified by the edit_id and tema parameters to index.php; and the (7) y, (8) ord, and (9) m parameters to sobre.php.

    Source:YEnH4ckEr
    Published:7 May 2009
    7.5
    High

    CVE-2009-1582

    Last Modified: 23 Apr 2026

    Million Dollar Text Links 1.0 does not properly restrict administrator access to admin.home.php, which allows remote attackers to bypass intended restrictions and gain privileges via a direct request to admin.home.php after visiting admin.php.

    Source:ThE g0bL!N
    Published:7 May 2009
    5
    Medium

    CVE-2009-1574

    Last Modified: 23 Apr 2026

    racoon/isakmp_frag.c in ipsec-tools before 0.7.2 allows remote attackers to cause a denial of service (crash) via crafted fragmented packets without a payload, which triggers a NULL pointer dereference.

    Source:mu-b
    Published:22 Apr 2009
    9.3
    Critical

    CVE-2009-1569

    Last Modified: 10 Mar 2011

    Multiple stack-based buffer overflows in Novell iPrint Client 4.38, 5.30, and possibly other versions before 5.32 allow remote attackers to execute arbitrary code via vectors related to (1) Date and (2) Time.

    Source:Metasploit
    Published:8 Dec 2009
    9.3
    Critical

    CVE-2009-1568

    Last Modified: 10 Mar 2011

    Stack-based buffer overflow in ienipp.ocx in Novell iPrint Client 5.30, and possibly other versions before 5.32, allows remote attackers to execute arbitrary code via a long target-frame parameter.

    Source:Metasploit
    Published:8 Dec 2009
    6.8
    Medium

    CVE-2009-1561

    Last Modified: 24 Jan 2017

    Cross-site request forgery (CSRF) vulnerability in administration.cgi on the Cisco Linksys WRT54GC router with firmware 1.05.7 allows remote attackers to hijack the intranet connectivity of arbitrary users for requests that change the administrator password via the sysPasswd and sysConfirmPasswd parameters.

    Source:Gabriel Lima
    Published:6 May 2009
    7.8
    High

    CVE-2009-1558

    Last Modified: 21 Apr 2014

    Directory traversal vulnerability in adm/file.cgi on the Cisco Linksys WVC54GCA wireless video camera with firmware 1.00R22 and 1.00R24 allows remote attackers to read arbitrary files via a %2e. (encoded dot dot) or an absolute pathname in the next_file parameter.

    Source:pagvac
    Published:6 May 2009
    4.3
    Medium

    CVE-2009-1557

    Last Modified: 21 Apr 2014

    Multiple cross-site scripting (XSS) vulnerabilities on the Cisco Linksys WVC54GCA wireless video camera with firmware 1.00R22 and 1.00R24 allow remote attackers to inject arbitrary web script or HTML via the next_file parameter to (1) main.cgi, (2) img/main.cgi, or (3) adm/file.cgi; or (4) the this_file parameter to adm/file.cgi.

    Source:pagvac
    Published:6 May 2009
    4.3
    Medium

    CVE-2009-1554

    Last Modified: 23 Apr 2014

    Cross-site scripting (XSS) vulnerability in ThemeServlet.java in Sun Woodstock 4.2, as used in Sun GlassFish Enterprise Server and other products, allows remote attackers to inject arbitrary web script or HTML via a UTF-7 string in the PATH_INFO, which is displayed on the 404 error page, as demonstrated by the PATH_INFO to theme/META-INF.

    Source:DSecRG
    Published:6 May 2009
    4.3
    Medium

    CVE-2009-1553

    Last Modified: 22 Apr 2014

    Multiple cross-site scripting (XSS) vulnerabilities in the Admin Console in Sun GlassFish Enterprise Server 2.1 allow remote attackers to inject arbitrary web script or HTML via the query string to (1) applications/applications.jsf, (2) configuration/configuration.jsf, (3) customMBeans/customMBeans.jsf, (4) resourceNode/resources.jsf, (5) sysnet/registration.jsf, or (6) webService/webServicesGeneral.jsf; or the name parameter to (7) configuration/auditModuleEdit.jsf, (8) configuration/httpListenerEdit.jsf, or (9) resourceNode/jdbcResourceEdit.jsf.

    Source:DSecRG
    Published:6 May 2009
    7.5
    High

    CVE-2009-1551

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Qt quickteam 2 allow remote attackers to execute arbitrary PHP code via a URL in the (1) qte_web_path parameter to qte_web.php and the (2) qte_root parameter to bin/qte_init.php.

    Source:ahmadbady
    Published:6 May 2009
    5
    Medium

    CVE-2009-1550

    Last Modified: 23 Apr 2026

    Zakkis Technology ABC Advertise 1.0 does not properly restrict access to admin.inc.php, which allows remote attackers to obtain the administrator login name and password via a direct request.

    Source:SirGod
    Published:6 May 2009
    7.5
    High

    CVE-2009-1549

    Last Modified: 23 Apr 2026

    AGTC MyShop 3.2b allows remote attackers to bypass authentication and obtain administrative access setting the log_accept cookie to "correcto."

    Source:Mr.tro0oqy
    Published:6 May 2009
    7.5
    High

    CVE-2009-1548

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in BluSky CMS allows remote attackers to execute arbitrary SQL commands via the news_id parameter in a read action.

    Source:snakespc
    Published:6 May 2009
    8.8
    High

    CVE-2009-1547

    Last Modified: 9 May 2014

    Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via a crafted data stream header that triggers memory corruption, aka "Data Stream Header Corruption Vulnerability."

    Source:Skylined
    Published:14 Oct 2009
    7.5
    High

    CVE-2009-1535

    Last Modified: 23 Apr 2026

    The WebDAV extension in Microsoft Internet Information Services (IIS) 5.1 and 6.0 allows remote attackers to bypass URI-based protection mechanisms, and list folders or read, create, or modify files, via a %c0%af (Unicode / character) at an arbitrary position in the URI, as demonstrated by inserting %c0%af into a "/protected/" initial pathname component to bypass the password protection on the protected\ folder, aka "IIS 5.1 and 6.0 WebDAV Authentication Bypass Vulnerability," a different vulnerability than CVE-2009-1122.

    Source:kingcope
    Published:10 Jun 2009
    9.3
    Critical

    CVE-2009-1534

    Last Modified: 10 Mar 2011

    Buffer overflow in the Office Web Components ActiveX Control in Microsoft Office XP SP3, Office 2000 Web Components SP3, Office XP Web Components SP3, BizTalk Server 2002, and Visual Studio .NET 2003 SP1 allows remote attackers to execute arbitrary code via crafted property values, aka "Office Web Components Buffer Overflow Vulnerability."

    Source:Metasploit
    Published:12 Aug 2009
    6.9
    Medium

    CVE-2009-1527

    Last Modified: 4 Sept 2016

    Race condition in the ptrace_attach function in kernel/ptrace.c in the Linux kernel before 2.6.30-rc4 allows local users to gain privileges via a PTRACE_ATTACH ptrace call during an exec system call that is launching a setuid application, related to locking an incorrect cred_exec_mutex object.

    Source:s0m3b0dy
    Published:5 May 2009
    6.9
    Medium

    CVE-2009-1526

    Last Modified: 21 Apr 2014

    JBMC Software DirectAdmin before 1.334 allows local users to create or overwrite any file via a symlink attack on an arbitrary file in a certain temporary directory, related to a request for this temporary file in the PATH_INFO to the CMD_DB script during a backup action.

    Source:anonymous
    Published:5 May 2009
    5
    Medium

    CVE-2009-1523

    Last Modified: 10 Mar 2015

    Directory traversal vulnerability in the HTTP server in Mort Bay Jetty 5.1.14, 6.x before 6.1.17, and 7.x through 7.0.0.M2 allows remote attackers to access arbitrary files via directory traversal sequences in the URI.

    Source:Alexey Sintsov
    Published:28 Apr 2009
    5
    Medium

    CVE-2009-1519

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in Pecio CMS 1.1.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the language parameter.

    Source:SirGod
    Published:4 May 2009
    4.3
    Medium

    CVE-2009-1517

    Last Modified: 23 Apr 2026

    Multiple insecure method vulnerabilities in the Symantec.EasySetup.1 ActiveX control in EasySetupInt.dll 14.0.4.30167 in the EasySetup wizard in Symantec Norton Ghost 14.0 allow remote attackers to cause a denial of service (browser crash) and possibly execute arbitrary code via unspecified input to the (1) GetBackupLocationPath, (2) CallUninstall, (3) SetupDeleteVolume, (4) CanUseEasySetup, (5) CallAddInitialProtection, and (6) CallTour methods.

    Source:shinnai
    Published:4 May 2009
    7.5
    High

    CVE-2009-1516

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the IceWarpServer.APIObject ActiveX control in api.dll in IceWarp Merak Mail Server 9.4.1 might allow context-dependent attackers to execute arbitrary code via a large value in the second argument to the Base64FileEncode method, as possibly demonstrated by a web application that accepts untrusted input for this method.

    Source:Nine:Situations:Group
    Published:4 May 2009
    5
    Medium

    CVE-2009-1514

    Last Modified: 23 Apr 2026

    Google Chrome 1.0.154.53 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a throw statement with a long exception value.

    Source:Aditya K Sood
    Published:4 May 2009
    6.5
    Medium

    CVE-2009-1512

    Last Modified: 23 Apr 2026

    Static code injection vulnerability in X-Forum 0.6.2 allows remote authenticated administrators to inject arbitrary PHP code into Config.php via the adminEMail parameter to SaveConfig.php.

    Source:Osirys
    Published:1 May 2009
    7.8
    High

    CVE-2009-1511

    Last Modified: 23 Apr 2026

    GDI+ in Microsoft Windows XP SP3 allows remote attackers to cause a denial of service (infinite loop) via a PNG file that contains a certain large btChunkLen value.

    Source:Code Audit Labs
    Published:1 May 2009
    7.5
    High

    CVE-2009-1510

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in KoschtIT Image Gallery 1.82 allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the file parameter to (1) ki_makepic.php and (2) ki_nojsdisplayimage.php in ki_base/.

    Source:ahmadbady
    Published:1 May 2009
    7.5
    High

    CVE-2009-1509

    Last Modified: 2 Jan 2017

    SQL injection vulnerability in ajaxp_backend.php in MyioSoft AjaxPortal 3.0 allows remote attackers to execute arbitrary SQL commands via the page parameter.

    Source:cOndemned
    Published:1 May 2009
    7.5
    High

    CVE-2009-1508

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the xforum_validateUser function in Common.php in X-Forum 0.6.2 allows remote attackers to execute arbitrary SQL commands, as demonstrated via the cookie_username parameter to Configure.php.

    Source:Osirys
    Published:1 May 2009
    6.8
    Medium

    CVE-2009-1506

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in classes/Xp.php in eLitius 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter to banner-details.php.

    Source:snakespc
    Published:1 May 2009
    7.5
    High

    CVE-2009-1504

    Last Modified: 23 Apr 2026

    Absolute Form Processor XE 1.5 allows remote attackers to bypass authentication and gain administrative access by setting the xlaAFPadmin cookie to "lvl=1&userid=1."

    Source:ZoRLu
    Published:1 May 2009
    7.5
    High

    CVE-2009-1503

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in login.php in Tiger Document Management System (DMS) allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.

    Source:ThE g0bL!N
    Published:1 May 2009
    7.5
    High

    CVE-2009-1502

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in plugin.php in S-Cms 1.1 Stable and 1.5.2 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the page parameter.

    Source:ZoRLu
    Published:1 May 2009
    6.8
    Medium

    CVE-2009-1500

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in ProjectCMS 1.0 Beta allows remote attackers to execute arbitrary SQL commands via the sn parameter.

    Source:YEnH4ckEr
    Published:1 May 2009
    7.5
    High

    CVE-2009-1499

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the MailTo (aka com_mailto) component in Joomla! allows remote attackers to execute arbitrary SQL commands via the article parameter in index.php. NOTE: SecurityFocus states that this issue has been disputed by the vendor.

    Source:H!tm@N
    Published:1 May 2009
    6.8
    Medium

    CVE-2009-1498

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in inc/profilemain.php in Game Maker 2k Internet Discussion Boards (iDB) 0.2.5 Pre-Alpha SVN 243 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the skin parameter in a settings action to profile.php.

    Source:LOTFREE
    Published:1 May 2009
    9.3
    Critical

    CVE-2009-1497

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in srt2smi.exe in Gretech Online Movie Player (GOM Player) 2.1.16.4635 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long string in an SRT file.

    Source:Bui Quang Minh
    Published:1 May 2009
    5
    Medium

    CVE-2009-1496

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the Cmi Marketplace (com_cmimarketplace) component 0.1 for Joomla! allows remote attackers to list arbitrary directories via a .. (dot dot) in the viewit parameter to index.php.

    Source:H!tm@N
    Published:1 May 2009
    5
    Medium

    CVE-2009-1495

    Last Modified: 23 Apr 2026

    Web File Explorer 3.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for data/db.mdb.

    Source:ByALBAYX
    Published:1 May 2009
    6.8
    Medium

    CVE-2009-1493

    Last Modified: 23 Apr 2026

    The customDictionaryOpen spell method in the JavaScript API in Adobe Reader 9.1, 8.1.4, 7.1.1, and earlier on Linux and UNIX allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a PDF file that triggers a call to this method with a long string in the second argument.

    Source:Arr1val
    Published:27 Apr 2009
    9.3
    Critical

    CVE-2009-1492

    Last Modified: 23 Apr 2026

    The getAnnots Doc method in the JavaScript API in Adobe Reader and Acrobat 9.1, 8.1.4, 7.1.1, and earlier allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a PDF file that contains an annotation, and has an OpenAction entry with JavaScript code that calls this method with crafted integer arguments.

    Source:Arr1val
    Published:27 Apr 2009
    5
    Medium

    CVE-2009-1490

    Last Modified: 23 Apr 2014

    Heap-based buffer overflow in Sendmail before 8.13.2 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via a long X- header, as demonstrated by an X-Testing header.

    Source:Simple Nomad
    Published:30 Apr 2009
    7.5
    High

    CVE-2009-1489

    Last Modified: 23 Apr 2026

    includes/user.php in Fungamez RC1 allows remote attackers to bypass authentication and gain administrative access by setting the user cookie parameter.

    Source:YEnH4ckEr
    Published:29 Apr 2009
    6.8
    Medium

    CVE-2009-1488

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in admin/load.php in FunGamez RC1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the module parameter to index.php.

    Source:YEnH4ckEr
    Published:29 Apr 2009
    7.5
    High

    CVE-2009-1487

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in pages/login.php in FunGamez RC1 allows remote attackers to execute arbitrary SQL commands via the login_user (aka username) parameter. NOTE: some of these details are obtained from third party information.

    Source:YEnH4ckEr
    Published:29 Apr 2009
    7.5
    High

    CVE-2009-1486

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in pmscript.php in Flatchat 3.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the with parameter.

    Source:SirGod
    Published:29 Apr 2009