7.5
    High

    CVE-2009-0726

    Last Modified: 17 Jan 2017

    SQL injection vulnerability in the GigCalendar (com_gigcal) component 1.0 for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the gigcal_gigs_id parameter in a details action to index.php.

    Source:boom3rang
    Published:24 Feb 2009
    7.5
    High

    CVE-2009-0722

    Last Modified: 8 Feb 2017

    Directory traversal vulnerability in admin.php in Potato News 1.0.0 allows remote attackers to include and execute arbitrary files via a .. (dot dot) in the user cookie parameter.

    Source:x0r
    Published:24 Feb 2009
    7.2
    High

    CVE-2009-0714

    Last Modified: 9 Nov 2016

    Unspecified vulnerability in the dpwinsup module (dpwinsup.dll) for dpwingad (dpwingad.exe) in HP Data Protector Express and Express SSE 3.x before build 47065, and Express and Express SSE 4.x before build 46537, allows remote attackers to cause a denial of service (application crash) or read portions of memory via one or more crafted packets.

    Source:Nibin
    Published:14 May 2009
    5
    Medium

    CVE-2009-0711

    Last Modified: 21 Dec 2016

    filter.php in PHPFootball 1.6 and earlier allows remote attackers to retrieve password hashes via a request with an Accounts value for the dbtable parameter, in conjunction with a Password value for the dbfield parameter. NOTE: this has been reported as a SQL injection vulnerability by some sources, but the provenance of that information is unknown.

    Source:KinG-LioN
    Published:23 Feb 2009
    4.3
    Medium

    CVE-2009-0710

    Last Modified: 21 Dec 2016

    Multiple cross-site scripting (XSS) vulnerabilities in PHPFootball 1.6 allow remote attackers to inject arbitrary web script or HTML via (1) the user parameter to login.php or (2) the dbfield parameter to filter.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:KinG-LioN
    Published:23 Feb 2009
    7.5
    High

    CVE-2009-0709

    Last Modified: 21 Dec 2016

    SQL injection vulnerability in login.php in PHPFootball 1.6 allows remote attackers to execute arbitrary SQL commands via the user parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:KinG-LioN
    Published:23 Feb 2009
    7.5
    High

    CVE-2009-0707

    Last Modified: 23 Jan 2017

    SQL injection vulnerability in admin/index.php in PowerClan 1.14a allows remote attackers to execute arbitrary SQL commands via the loginemail parameter (aka login field). NOTE: some of these details are obtained from third party information.

    Source:Virangar Security
    Published:23 Feb 2009
    6.8
    Medium

    CVE-2009-0705

    Last Modified: 14 Nov 2016

    SQL injection vulnerability in news.php in PowerScripts PowerNews 2.5.4, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the newsid parameter.

    Source:Virangar Security
    Published:23 Feb 2009
    7.5
    High

    CVE-2009-0704

    Last Modified: 12 Jan 2017

    SQL injection vulnerability in search.php in WSN Guest 1.23 allows remote attackers to execute arbitrary SQL commands via the search parameter in an advanced action.

    Source:DaiMon
    Published:23 Feb 2009
    7.5
    High

    CVE-2009-0703

    Last Modified: 11 Jan 2017

    SQL injection vulnerability in bview.asp in ASPThai.Net Webboard 6.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:DaiMon
    Published:23 Feb 2009
    7.5
    High

    CVE-2009-0702

    Last Modified: 12 Jan 2017

    SQL injection vulnerability in the Phoca Documentation (com_phocadocumentation) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a section action to index.php.

    Source:EcHoLL
    Published:23 Feb 2009
    6.8
    Medium

    CVE-2009-0701

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in index.php in Cybershade CMS 0.2b, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) THEME_header and (2) THEME_footer parameters.

    Source:JosS
    Published:23 Feb 2009
    4
    Medium

    CVE-2009-0700

    Last Modified: 7 Apr 2014

    Plunet BusinessManager 4.1 and earlier allows remote authenticated users to bypass access restrictions and (1) read sensitive Customer or Order data via a modified Pfad parameter to pagesUTF8/Sys_DirAnzeige.jsp, or (2) list sensitive Jobs via a direct request to pagesUTF8/auftrag_job.jsp.

    Source:Matteo Ignaccolo
    Published:23 Feb 2009
    3.5
    Low

    CVE-2009-0699

    Last Modified: 7 Apr 2014

    Cross-site scripting (XSS) vulnerability in pagesUTF8/auftrag_allgemeinauftrag.jsp in Plunet BusinessManager 4.1 and earlier allows remote authenticated users to inject arbitrary web script or HTML via the (1) QUB and (2) Bez74 parameters.

    Source:Matteo Ignaccolo
    Published:23 Feb 2009
    4.3
    Medium

    CVE-2009-0696

    Last Modified: 23 Apr 2026

    The dns_db_findrdataset function in db.c in named in ISC BIND 9.4 before 9.4.3-P3, 9.5 before 9.5.1-P3, and 9.6 before 9.6.1-P1, when configured as a master server, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via an ANY record in the prerequisite section of a crafted dynamic update message.

    Source:kingcope
    Published:28 Jul 2009
    7.5
    High

    CVE-2009-0695

    Last Modified: 1 Apr 2017

    hagent.exe in Wyse Device Manager (WDM) 4.7.x does not require authentication for commands, which allows remote attackers to obtain management access via a crafted query, as demonstrated by a V52 query that triggers a power-off action.

    Source:it.solunium
    Published:19 Jun 2012
    7.5
    High

    CVE-2009-0693

    Last Modified: 1 Apr 2017

    Multiple buffer overflows in Wyse Device Manager (WDM) 4.7.x allow remote attackers to execute arbitrary code via (1) the User-Agent HTTP header to hserver.dll or (2) unspecified input to hagent.exe.

    Source:it.solunium
    Published:19 Jun 2012
    10
    Critical

    CVE-2009-0692

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the script_write_params method in client/dhclient.c in ISC DHCP dhclient 4.1 before 4.1.0p1, 4.0 before 4.0.1p1, 3.1 before 3.1.2p1, 3.0, and 2.0 allows remote DHCP servers to execute arbitrary code via a crafted subnet-mask option.

    Source:Jon Oberheide
    Published:14 Jul 2009
    6.8
    Medium

    CVE-2009-0689

    Last Modified: 23 Apr 2026

    Array index error in the (1) dtoa implementation in dtoa.c (aka pdtoa.c) and the (2) gdtoa (aka new dtoa) implementation in gdtoa/misc.c in libc, as used in multiple operating systems and products including in FreeBSD 6.4 and 7.2, NetBSD 5.0, OpenBSD 4.5, Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4, K-Meleon 1.5.3, SeaMonkey 1.1.8, and other products, allows context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a large precision value in the format argument to a printf function, which triggers incorrect memory allocation and a heap-based buffer overflow during conversion to a floating-point number.

    Source:Maksymilian Arciemowicz & sp3x
    Published:1 Jul 2009
    7.8
    High

    CVE-2009-0687

    Last Modified: 23 Apr 2026

    The pf_test_rule function in OpenBSD Packet Filter (PF), as used in OpenBSD 4.2 through 4.5, NetBSD 5.0 before RC3, MirOS 10 and earlier, and MidnightBSD 0.3-current allows remote attackers to cause a denial of service (panic) via crafted IP packets that trigger a NULL pointer dereference during translation, related to an IPv4 packet with an ICMPv6 payload.

    Source:Rembrandt
    Published:11 Aug 2009
    7.2
    High

    CVE-2009-0686

    Last Modified: 23 Apr 2026

    The TrendMicro Activity Monitor Module (tmactmon.sys) 2.52.0.1002 in Trend Micro Internet Pro 2008 and 2009, and Security Pro 2008 and 2009, allows local users to gain privileges via a crafted IRP in a METHOD_NEITHER IOCTL request to \Device\tmactmon that overwrites memory.

    Source:b1@ckeYe
    Published:1 Apr 2009
    7.8
    High

    CVE-2009-0680

    Last Modified: 23 Apr 2026

    cgi-bin/welcome/VPN_only in the web interface in Netgear SSL312 allows remote attackers to cause a denial of service (device crash) via a crafted query string, as demonstrated using directory traversal sequences.

    Source:Rembrandt
    Published:22 Feb 2009
    5
    Medium

    CVE-2009-0678

    Last Modified: 23 Apr 2026

    images/captcha.php in RavenNuke 2.30 allows remote attackers to obtain sensitive information via an aFonts array parameter value that does not correspond to a valid font file, which reveals the installation path in an error message.

    Source:waraxe
    Published:22 Feb 2009
    6.5
    Medium

    CVE-2009-0677

    Last Modified: 23 Apr 2026

    avatarlist.php in the Your Account module, reached through modules.php, in Raven Web Services RavenNuke 2.30 allows remote authenticated users to execute arbitrary code via PHP sequences in an element of the replacements array, which is processed by the preg_replace function with the eval switch, as specified in an element of the patterns array.

    Source:waraxe
    Published:22 Feb 2009
    2.1
    Low

    CVE-2009-0676

    Last Modified: 6 Sept 2016

    The sock_getsockopt function in net/core/sock.c in the Linux kernel before 2.6.28.6 does not initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel memory via an SO_BSDCOMPAT getsockopt request.

    Source:Clément Lecigne
    Published:11 Feb 2009
    6
    Medium

    CVE-2009-0674

    Last Modified: 23 Apr 2026

    images/captcha.php in Raven Web Services RavenNuke 2.30, when register_globals and display_errors are enabled, allows remote attackers to determine the existence of local files by sending requests with full pathnames in the aFonts array parameter, and then observing the error messages, which differ between existing and nonexistent pathnames.

    Source:waraxe
    Published:22 Feb 2009
    6.5
    Medium

    CVE-2009-0673

    Last Modified: 23 Apr 2026

    Eval injection vulnerability in the Custom Fields feature in the Your Account module in Raven Web Services RavenNuke 2.30 allows remote authenticated administrators to execute arbitrary PHP code via the ID Field Name box in a yaCustomFields action to admin.php.

    Source:waraxe
    Published:22 Feb 2009
    6.5
    Medium

    CVE-2009-0672

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Resend_Email module in Raven Web Services RavenNuke 2.30 allows remote authenticated administrators to execute arbitrary SQL commands via the user_prefix parameter to modules.php.

    Source:waraxe
    Published:22 Feb 2009
    5
    Medium

    CVE-2009-0659

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the GetStatsFromLine function in TPTEST 3.1.7 allows remote attackers to have an unknown impact via a STATS line with a long email field. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:ffwd
    Published:20 Feb 2009
    7.8
    High

    CVE-2009-0658

    Last Modified: 23 Apr 2026

    Buffer overflow in Adobe Reader 9.0 and earlier, and Acrobat 9.0 and earlier, allows remote attackers to execute arbitrary code via a crafted PDF document, related to a non-JavaScript function call and possibly an embedded JBIG2 image stream, as exploited in the wild in February 2009 by Trojan.Pidief.E.

    Source:Guido Landi
    Published:19 Feb 2009
    10
    Critical

    CVE-2009-0650

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the GetStatsFromLine function in TPTEST 3.1.7 and earlier, and possibly 5.02, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a STATS line with a long pwd field. NOTE: some of these details are obtained from third party information.

    Source:ffwd
    Published:20 Feb 2009
    7.8
    High

    CVE-2009-0649

    Last Modified: 13 Feb 2017

    The web browser in Symbian OS on the Nokia N95 cell phone allows remote attackers to cause a denial of service (crash) via JavaScript code that calls the setAttributeNode method.

    Source:Juan Yacubian
    Published:20 Feb 2009
    7.5
    High

    CVE-2009-0646

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in 4Site CMS 2.6 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) login and (2) password parameters to pcgi/4site.pl, (3) page parameter to print/print.shtml, (4) s and (5) i parameters to portfolio/index.shtml, (6) h parameter to hotel/index.php, (7) id parameter to news/news1.shtml, and the (8) th parameter to faq/index.shtml.

    Source:D.Mortalov
    Published:18 Feb 2009
    6.5
    Medium

    CVE-2009-0645

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in Jaws 0.8.8 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the (1) language, (2) Introduction_complete, and (3) use_log parameters, different vectors than CVE-2004-2445.

    Source:fuzion
    Published:18 Feb 2009
    5.1
    Medium

    CVE-2009-0643

    Last Modified: 23 Apr 2026

    Static code injection vulnerability in post.php in Simple PHP News 1.0 final allows remote attackers to inject arbitrary PHP code into news.txt via the post parameter, and then execute the code via a direct request to display.php. NOTE: some of these details are obtained from third party information.

    Source:Osirys
    Published:18 Feb 2009
    9.3
    Critical

    CVE-2009-0641

    Last Modified: 23 Apr 2026

    sys_term.c in telnetd in FreeBSD 7.0-RELEASE and other 7.x versions deletes dangerous environment variables with a method that was valid only in older FreeBSD distributions, which might allow remote attackers to execute arbitrary code by passing a crafted environment variable from a telnet client, as demonstrated by an LD_PRELOAD value that references a malicious library.

    Source:kingcope
    Published:18 Feb 2009
    5
    Medium

    CVE-2009-0640

    Last Modified: 11 Apr 2014

    Directory traversal vulnerability in the administrative web server in Swann DVR4-SecuraNet allows remote attackers to read arbitrary files via a .. (dot dot) in the URI, as demonstrated by reading the vy_netman.cfg file that contains passwords.

    Source:Terry Froy
    Published:18 Feb 2009
    7.5
    High

    CVE-2009-0639

    Last Modified: 8 Feb 2017

    PHP remote file inclusion vulnerability in moduli/libri/index.php in phpyabs 0.1.2 allows remote attackers to execute arbitrary PHP code via a URL in the Azione parameter.

    Source:Arka69
    Published:18 Feb 2009
    4.3
    Medium

    CVE-2009-0611

    Last Modified: 11 Apr 2014

    Multiple cross-site scripting (XSS) vulnerabilities in qfsearch/AdminServlet in QuickFinder Server in Novell Open Enterprise Server 1.x allow remote attackers to inject arbitrary web script or HTML via (1) the siteloc parameter in a displayaddsite action, the site parameter in a (2) generalproperties or (3) clusterserviceproperties action, (4) the adminurl parameter in a global action, or (5) the print-list parameter.

    Source:Ivan Sanchez
    Published:17 Feb 2009
    7.5
    High

    CVE-2009-0610

    Last Modified: 23 Apr 2026

    Multiple static code injection vulnerabilities in post.php in Simple PHP News 1.0 final allow remote attackers to inject arbitrary PHP code into news.txt via the (1) title or (2) date parameter, and then execute the code via a direct request to display.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Osirys
    Published:17 Feb 2009
    7.5
    High

    CVE-2009-0604

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in PHP Director 0.21 and earlier allows remote attackers to execute arbitrary SQL commands via the searching parameter.

    Source:darkjoker
    Published:16 Feb 2009
    7.5
    High

    CVE-2009-0602

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in upload.php in WikkiTikkiTavi 1.11 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in img/.

    Source:ByALBAYX
    Published:16 Feb 2009
    7.5
    High

    CVE-2009-0598

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in PhpMesFilms 1.0 and 1.8 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:SuB-ZeRo
    Published:16 Feb 2009
    6.8
    Medium

    CVE-2009-0597

    Last Modified: 4 Jan 2017

    SQL injection vulnerability in admin/index.php in w3b>cms (aka w3blabor CMS) before 3.4.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the benutzername parameter (aka Username field) in a login action.

    Source:DNX
    Published:16 Feb 2009
    6.8
    Medium

    CVE-2009-0596

    Last Modified: 23 Jan 2017

    Directory traversal vulnerability in skysilver/login.tpl.php in phpSkelSite 1.4, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the TplSuffix parameter.

    Source:ahmadbady
    Published:16 Feb 2009
    5.1
    Medium

    CVE-2009-0595

    Last Modified: 23 Jan 2017

    PHP remote file inclusion vulnerability in skysilver/login.tpl.php in phpSkelSite 1.4, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary PHP code via a URL in the theme parameter.

    Source:ahmadbady
    Published:16 Feb 2009
    4.3
    Medium

    CVE-2009-0594

    Last Modified: 23 Jan 2017

    Cross-site scripting (XSS) vulnerability in index.php in phpSkelSite 1.4 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.

    Source:ahmadbady
    Published:16 Feb 2009
    6.5
    Medium

    CVE-2009-0593

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in members.php in plx Auto Reminder 3.7 allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a newar action.

    Source:ZoRLu
    Published:16 Feb 2009
    7.5
    High

    CVE-2009-0592

    Last Modified: 23 Jan 2017

    Multiple directory traversal vulnerabilities in PNphpBB2 1.2i and earlier allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the ModName parameter to (1) admin_words.php, (2) admin_groups_reapir.php, (3) admin_smilies.php, (4) admin_ranks.php, (5) admin_styles.php, and (6) admin_users.php in admin/.

    Source:StAkeR
    Published:16 Feb 2009
    4.3
    Medium

    CVE-2009-0580

    Last Modified: 25 Apr 2014

    Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18, when FORM authentication is used, allows remote attackers to enumerate valid usernames via requests to /j_security_check with malformed URL encoding of passwords, related to improper error checking in the (1) MemoryRealm, (2) DataSourceRealm, and (3) JDBCRealm authentication realms, as demonstrated by a % (percent) value for the j_password parameter.

    Source:D. Matscheko
    Published:3 Jun 2009