7.5
    High

    CVE-2009-0574

    Last Modified: 29 Dec 2016

    SQL injection vulnerability in index.php in Easy CafeEngine allows remote attackers to execute arbitrary SQL commands via the catid parameter, a different vector than CVE-2008-4604.

    Source:SuNHouSe2
    Published:13 Feb 2009
    4.3
    Medium

    CVE-2009-0573

    Last Modified: 10 Apr 2014

    Multiple cross-site scripting (XSS) vulnerabilities in FotoWeb 6.0 (Build 273) allow remote attackers to inject arbitrary web script or HTML via the (1) s parameter to cmdrequest/Login.fwx and the (2) search parameter to Grid.fwx.

    Source:Stelios Tigkas
    Published:13 Feb 2009
    5.1
    Medium

    CVE-2009-0572

    Last Modified: 5 Jan 2017

    PHP remote file inclusion vulnerability in include/flatnux.php in FlatnuX CMS (aka Flatnuke3) 2009-01-27 and 2009-02-04, when register_globals is enabled and magic_quotes_gpc disabled, allows remote attackers to execute arbitrary PHP code via a URL in the _FNROOTPATH parameter to (1) index.php and (2) filemanager.php.

    Source:Alfons Luja
    Published:13 Feb 2009
    5
    Medium

    CVE-2009-0571

    Last Modified: 23 Apr 2026

    admin.php in Ninja Designs Mailist 3.0 stores backup copies of maillist.php under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to the backup directory.

    Source:SirGod
    Published:13 Feb 2009
    5.1
    Medium

    CVE-2009-0570

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in send.php in Ninja Designs Mailist 3.0, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the load parameter. NOTE: some of these details are obtained from third party information.

    Source:SirGod
    Published:13 Feb 2009
    9.3
    Critical

    CVE-2009-0565

    Last Modified: 20 Aug 2010

    Buffer overflow in Microsoft Office Word 2000 SP3, 2002 SP3, and 2007 SP1 and SP2; Microsoft Office for Mac 2004 and 2008; Open XML File Format Converter for Mac; and Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allows remote attackers to execute arbitrary code via a Word document with a malformed record that triggers memory corruption, aka "Word Buffer Overflow Vulnerability."

    Source:anonymous
    Published:10 Jun 2009
    9.3
    Critical

    CVE-2009-0553

    Last Modified: 23 Apr 2026

    Microsoft Internet Explorer 6 SP1, 6 and 7 on Windows XP SP2 and SP3, 6 and 7 on Windows Server 2003 SP1 and SP2, 7 on Windows Vista Gold and SP1, and 7 on Windows Server 2008 allows remote attackers to execute arbitrary code via a web page that triggers presence of an object in memory that was (1) not properly initialized or (2) deleted, aka "Uninitialized Memory Corruption Vulnerability."

    Source:Skylined
    Published:15 Apr 2009
    9.3
    Critical

    CVE-2009-0546

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in NewsGator FeedDemon 2.7 and earlier allows user-assisted remote attackers to execute arbitrary code via a long text attribute in an outline element in a .opml file.

    Source:Praveen Darshanam
    Published:12 Feb 2009
    10
    Critical

    CVE-2009-0545

    Last Modified: 23 Apr 2026

    cgi-bin/kerbynet in ZeroShell 1.0beta11 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the type parameter in a NoAuthREQ x509List action.

    Source:ikki
    Published:12 Feb 2009
    10
    Critical

    CVE-2009-0544

    Last Modified: 10 Apr 2014

    Buffer overflow in the PyCrypto ARC2 module 2.0.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large ARC2 key length.

    Source:Mike Wiacek
    Published:7 Feb 2009
    6.8
    Medium

    CVE-2009-0543

    Last Modified: 27 Oct 2016

    ProFTPD Server 1.3.1, with NLS support enabled, allows remote attackers to bypass SQL injection protection mechanisms via invalid, encoded multibyte characters, which are not properly handled in (1) mod_sql_mysql and (2) mod_sql_postgres.

    Source:gat3way
    Published:12 Feb 2009
    7.5
    High

    CVE-2009-0542

    Last Modified: 27 Oct 2016

    SQL injection vulnerability in ProFTPD Server 1.3.1 through 1.3.2rc2 allows remote attackers to execute arbitrary SQL commands via a "%" (percent) character in the username, which introduces a "'" (single quote) character during variable substitution by mod_sql.

    Source:gat3way
    Published:10 Feb 2009
    4.3
    Medium

    CVE-2009-0541

    Last Modified: 11 Apr 2014

    Multiple cross-site scripting (XSS) vulnerabilities in Magento 1.2.0 and 1.2.1.1 allow remote attackers to inject arbitrary web script or HTML via (1) the username field in an admin/ request to index.php, possibly related to the login[username] parameter and the app/code/core/Mage/Admin/Model/Session.php login function; (2) the email address field in an admin/index/forgotpassword/ request to index.php, possibly related to the email parameter and the app/code/core/Mage/Adminhtml/controllers/IndexController.php forgotpasswordAction function; or (3) the return parameter to the default URI under downloader/.

    Source:Loukas Kalenderidis
    Published:25 Feb 2009
    4.9
    Medium

    CVE-2009-0537

    Last Modified: 23 Apr 2026

    Integer overflow in the fts_build function in fts.c in libc in (1) OpenBSD 4.4 and earlier and (2) Microsoft Interix 6.0 build 10.0.6030.0 allows context-dependent attackers to cause a denial of service (application crash) via a deep directory tree, related to the fts_level structure member, as demonstrated by (a) du, (b) rm, (c) chmod, and (d) chgrp on OpenBSD; and (e) SearchIndexer.exe on Vista Enterprise.

    Source:SecurityReason
    Published:9 Mar 2009
    7.5
    High

    CVE-2009-0535

    Last Modified: 8 Feb 2017

    Directory traversal vulnerability in export.php in Thyme 1.3 and earlier, when register_globals is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the export_to parameter.

    Source:cheverok
    Published:11 Feb 2009
    7.5
    High

    CVE-2009-0534

    Last Modified: 8 Feb 2017

    SQL injection vulnerability in FlexCMS allows remote attackers to execute arbitrary SQL commands via the catId parameter.

    Source:MisterRichard
    Published:11 Feb 2009
    7.5
    High

    CVE-2009-0531

    Last Modified: 8 Feb 2017

    SQL injection vulnerability in gallery/view.asp in A Better Member-Based ASP Photo Gallery before 1.2 allows remote attackers to execute arbitrary SQL commands via the entry parameter.

    Source:BackDoor
    Published:11 Feb 2009
    6.8
    Medium

    CVE-2009-0530

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in SnippetMaster 2.2.2, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) _SESSION[SCRIPT_PATH] parameter to includes/vars.inc.php and the (2) g_pcltar_lib_dir parameter to includes/tar_lib/pcltar.lib.php.

    Source:RoMaNcYxHaCkEr
    Published:11 Feb 2009
    4.3
    Medium

    CVE-2009-0529

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in SnippetMaster Webpage Editor 2.2.2 allows remote attackers to inject arbitrary web script or HTML via the language parameter.

    Source:RoMaNcYxHaCkEr
    Published:11 Feb 2009
    7.5
    High

    CVE-2009-0528

    Last Modified: 8 Feb 2017

    SQL injection vulnerability in frame.php in Rhadrix If-CMS 2.07 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:darkjoker
    Published:11 Feb 2009
    6.8
    Medium

    CVE-2009-0527

    Last Modified: 30 Dec 2016

    PHP remote file inclusion vulnerability in plugins/rss_importer_functions.php in AdaptCMS Lite 1.4 allows remote attackers to execute arbitrary PHP code via a URL in the sitepath parameter.

    Source:RoMaNcYxHaCkEr
    Published:11 Feb 2009
    4.3
    Medium

    CVE-2009-0526

    Last Modified: 30 Dec 2016

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in AdaptCMS Lite 1.4 allow remote attackers to inject arbitrary web script or HTML via the (1) url and (2) acuparam parameters, and (3) the URI.

    Source:RoMaNcYxHaCkEr
    Published:11 Feb 2009
    9.3
    Critical

    CVE-2009-0520

    Last Modified: 11 Apr 2014

    Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 does not properly remove references to destroyed objects during Shockwave Flash file processing, which allows remote attackers to execute arbitrary code via a crafted file, related to a "buffer overflow issue."

    Source:Javier Vicente Vallejo
    Published:24 Feb 2009
    10
    Critical

    CVE-2009-0517

    Last Modified: 24 Jan 2017

    Eval injection vulnerability in index.php in phpSlash 0.8.1.1 and earlier allows remote attackers to execute arbitrary PHP code via the fields parameter, which is supplied to an eval function call within the generic function in include/class/tz_env.class. NOTE: some of these details are obtained from third party information.

    Source:DarkFig
    Published:11 Feb 2009
    7.5
    High

    CVE-2009-0516

    Last Modified: 8 Feb 2017

    SQL injection vulnerability in the classified page (classified.php) in BusinessSpace 1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.

    Source:K-159
    Published:11 Feb 2009
    6.8
    Medium

    CVE-2009-0515

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in check_lang.php in Yet Another NOCC (YANOCC) 0.1.0 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter.

    Source:Kacper
    Published:11 Feb 2009
    7.5
    High

    CVE-2009-0514

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in WebFrame 0.76 allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the (1) currentmod and (2) LANG parameters to mod/index.php.

    Source:ahmadbady
    Published:11 Feb 2009
    7.5
    High

    CVE-2009-0513

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in WebFrame 0.76 allow remote attackers to execute arbitrary PHP code via a URL in the classFiles parameter to (1) admin/doc/index.php, (2) index.php, and (3) base/menu.php in mod/.

    Source:ahmadbady
    Published:11 Feb 2009
    5
    Medium

    CVE-2009-0498

    Last Modified: 23 Apr 2026

    Virtual GuestBook (vgbook) 2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request to guestbook.mdb.

    Source:Moudi
    Published:10 Feb 2009
    5
    Medium

    CVE-2009-0497

    Last Modified: 3 Apr 2014

    Directory traversal vulnerability in log.jsp in Ignite Realtime Openfire 3.6.2 allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in the log parameter.

    Source:Federico Muttis
    Published:10 Feb 2009
    4.3
    Medium

    CVE-2009-0496

    Last Modified: 3 Apr 2014

    Multiple cross-site scripting (XSS) vulnerabilities in Ignite Realtime Openfire 3.6.2 allow remote attackers to inject arbitrary web script or HTML via the (1) log parameter to (a) logviewer.jsp and (b) log.jsp; (2) search parameter to (c) group-summary.jsp; (3) username parameter to (d) user-properties.jsp; (4) logDir, (5) maxTotalSize, (6) maxFileSize, (7) maxDays, and (8) logTimeout parameters to (e) audit-policy.jsp; (9) propName parameter to (f) server-properties.jsp; and the (10) roomconfig_roomname and (11) roomconfig_roomdesc parameters to (g) muc-room-edit-form.jsp. NOTE: this can be leveraged for arbitrary code execution by using XSS to upload a malicious plugin.

    Source:Federico Muttis
    Published:10 Feb 2009
    7.5
    High

    CVE-2009-0495

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in include/define.php in REALTOR 747 4.11 allows remote attackers to execute arbitrary PHP code via a URL in the INC_DIR parameter.

    Source:ahmadbady
    Published:10 Feb 2009
    7.5
    High

    CVE-2009-0494

    Last Modified: 16 Jan 2017

    SQL injection vulnerability in the Portfol (com_portfol) 1.2 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the vcatid parameter in a viewcategory action to index.php.

    Source:H!tm@N
    Published:10 Feb 2009
    7.5
    High

    CVE-2009-0493

    Last Modified: 25 Nov 2016

    SQL injection vulnerability in login.php in IT!CMS 2.1a and earlier allows remote attackers to execute arbitrary SQL commands via the Username.

    Source:certaindeath
    Published:10 Feb 2009
    9.3
    Critical

    CVE-2009-0491

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Elecard MPEG Player 5.5 build 15884.081218 allows remote attackers to execute arbitrary code via a M3U file containing a long URL.

    Source:aBo MoHaMeD
    Published:10 Feb 2009
    9.3
    Critical

    CVE-2009-0490

    Last Modified: 21 Feb 2013

    Stack-based buffer overflow in the String_parse::get_nonspace_quoted function in lib-src/allegro/strparse.cpp in Audacity 1.2.6 and other versions before 1.3.6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a .gro file containing a long string.

    Source:Houssamix
    Published:2 Jan 2009
    7.5
    High

    CVE-2009-0479

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in admin/admin_login.php in Online Grades 3.2.4 allow remote attackers to execute arbitrary SQL commands via the (1) uname or (2) pword parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:x0r
    Published:9 Feb 2009
    5
    Medium

    CVE-2009-0478

    Last Modified: 23 Apr 2026

    Squid 2.7 to 2.7.STABLE5, 3.0 to 3.0.STABLE12, and 3.1 to 3.1.0.4 allows remote attackers to cause a denial of service via an HTTP request with an invalid version number, which triggers a reachable assertion in (1) HttpMsg.c and (2) HttpStatusLine.c.

    Source:Praveen Darshanam
    Published:2 Feb 2009
    9.3
    Critical

    CVE-2009-0476

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in MultiMedia Soft AdjMmsEng.dll 7.11.1.0 and 7.11.2.7, as distributed in multiple MultiMedia Soft audio components for .NET, allows remote attackers to execute arbitrary code via a long string in a playlist (.pls) file, as originally reported for Euphonics Audio Player 1.0. NOTE: some of these details are obtained from third party information.

    Source:germaya_x
    Published:8 Feb 2009
    6.8
    Medium

    CVE-2009-0473

    Last Modified: 23 Apr 2026

    Open redirect vulnerability in the web interface in the Rockwell Automation ControlLogix 1756-ENBT/A EtherNet/IP Bridge Module allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

    Published:6 Feb 2009
    4.3
    Medium

    CVE-2009-0470

    Last Modified: 10 Apr 2014

    Multiple cross-site scripting (XSS) vulnerabilities in the HTTP server in Cisco IOS 12.4(23) allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default URI under (1) level/15/exec/-/ or (2) exec/, a different vulnerability than CVE-2008-3821.

    Source:Zloss
    Published:6 Feb 2009
    6.8
    Medium

    CVE-2009-0468

    Last Modified: 23 Apr 2026

    Multiple cross-site request forgery (CSRF) vulnerabilities in ajax.html in Profense Web Application Firewall 2.6.2 and 2.6.3 allow remote attackers to hijack the authentication of administrators for requests that (1) shutdown the server, (2) send ping packets, (3) enable network services, (4) configure a proxy server, and (5) modify other settings via parameters in the query string.

    Source:Michael Brooks
    Published:6 Feb 2009
    4.3
    Medium

    CVE-2009-0467

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in proxy.html in Profense Web Application Firewall 2.6.2 and 2.6.3 allows remote attackers to inject arbitrary web script or HTML via the proxy parameter in a deny_log manage action.

    Source:Michael Brooks
    Published:6 Feb 2009
    9.3
    Critical

    CVE-2009-0465

    Last Modified: 23 Apr 2026

    The SaveDoc method in the All_In_The_Box.AllBox ActiveX control in ALL_IN_THE_BOX.OCX in Synactis ALL In-The-Box ActiveX 3 allows remote attackers to create and overwrite arbitrary files via an argument ending in a '\0' character, which bypasses the intended .box filename extension, as demonstrated by a C:\boot.ini\0 argument.

    Source:DSecRG
    Published:6 Feb 2009
    5.1
    Medium

    CVE-2009-0464

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in includes/header.php in Groone GBook 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the abspath parameter.

    Source:k3vin mitnick
    Published:6 Feb 2009
    6.8
    Medium

    CVE-2009-0463

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in includes/header.php in Groone GLinks 2.1 allows remote attackers to execute arbitrary PHP code via a URL in the abspath parameter.

    Source:k3vin mitnick
    Published:6 Feb 2009
    7.5
    High

    CVE-2009-0462

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in customer_login_check.asp in ClickTech ClickCart 6.0 allow remote attackers to execute arbitrary SQL commands via (1) the txtEmail parameter (aka E-MAIL field) or (2) the txtPassword parameter (aka password field) to customer_login.asp. NOTE: some of these details are obtained from third party information.

    Source:R3d-D3V!L
    Published:6 Feb 2009
    7.5
    High

    CVE-2009-0461

    Last Modified: 23 Apr 2026

    Whole Hog Password Protect: Enhanced 1.x allows remote attackers to bypass authentication and obtain administrative access via an integer value in the adminid cookie.

    Source:Stack
    Published:6 Feb 2009
    7.5
    High

    CVE-2009-0460

    Last Modified: 23 Apr 2026

    Whole Hog Ware Support 1.x allows remote attackers to bypass authentication and obtain administrative access via an integer value in the adminid cookie.

    Source:Stack
    Published:6 Feb 2009
    7.5
    High

    CVE-2009-0459

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in admin/login_submit.php in Whole Hog Password Protect: Enhanced 1.x allow remote attackers to execute arbitrary SQL commands via (1) the uid parameter (aka Username field) or (2) the pwd parameter (aka Password field). NOTE: some of these details are obtained from third party information.

    Source:ByALBAYX
    Published:6 Feb 2009