7.5
    High

    CVE-2009-0458

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in admin/login_submit.php in Whole Hog Ware Support 1.x allow remote attackers to execute arbitrary SQL commands via (1) the uid parameter (aka Username field) or (2) the pwd parameter (aka Password field). NOTE: some of these details are obtained from third party information.

    Source:ByALBAYX
    Published:6 Feb 2009
    7.5
    High

    CVE-2009-0457

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in AJA Portal 1.2 allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the currentlang parameter to admin/case.php in the (1) Contact_Plus and (2) Reviews modules, and (3) the module_name parameter to admin/includes/FANCYNLOptions.php in the Fancy_NewsLetter module.

    Source:ahmadbady
    Published:6 Feb 2009
    7.5
    High

    CVE-2009-0456

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in examples/example_clientside_javascript.php in patForms, as used in Sourdough 0.3.5, allows remote attackers to execute arbitrary PHP code via a URL in the neededFiles[patForms] parameter.

    Source:ahmadbady
    Published:6 Feb 2009
    2.6
    Low

    CVE-2009-0455

    Last Modified: 10 Apr 2014

    Cross-site scripting (XSS) vulnerability in the anonymous comments feature in lib-comment.php in glFusion 1.1.0, 1.1.1, and earlier versions allows remote attackers to inject arbitrary web script or HTML via the username parameter to comment.php.

    Source:Bjarne Mathiesen Schacht
    Published:11 Feb 2009
    5
    Medium

    CVE-2009-0453

    Last Modified: 23 Apr 2026

    Online Grades 3.2.4 allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function.

    Source:x0r
    Published:5 Feb 2009
    6.8
    Medium

    CVE-2009-0452

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in parents/login.php in Online Grades 3.2.4, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) uname or (2) pass parameter.

    Source:x0r
    Published:5 Feb 2009
    7.5
    High

    CVE-2009-0451

    Last Modified: 22 Dec 2016

    SQL injection vulnerability in Skalfa SkaLinks 1.5 allows remote attackers to execute arbitrary SQL commands via the Admin name field to the default URI under admin/.

    Source:Dimi4
    Published:5 Feb 2009
    9.3
    Critical

    CVE-2009-0450

    Last Modified: 28 Apr 2011

    Stack-based buffer overflow in BlazeVideo HDTV Player 3.5 and earlier allows remote attackers to execute arbitrary code via a long string in a playlist (aka .plf) file.

    Source:ThE g0bL!N
    Published:5 Feb 2009
    7.2
    High

    CVE-2009-0449

    Last Modified: 11 Apr 2014

    Buffer overflow in klim5.sys in Kaspersky Anti-Virus for Workstations 6.0 and Anti-Virus 2008 allows local users to gain privileges via an IOCTL 0x80052110 call.

    Source:Ruben Santamarta
    Published:5 Feb 2009
    7.5
    High

    CVE-2009-0448

    Last Modified: 1 Feb 2017

    Directory traversal vulnerability in admin/modules/aa/preview.php in Syntax Desktop 2.7 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the synTarget parameter.

    Source:ahmadbady
    Published:5 Feb 2009
    7.5
    High

    CVE-2009-0447

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in default.asp in MyDesign Sayac 2.0 allow remote attackers to execute arbitrary SQL commands via (1) the user parameter (aka UserName field) or (2) the pass parameter (aka Pass field) to (a) admin/admin.asp or (b) the default URI under admin/. NOTE: some of these details are obtained from third party information.

    Source:Kacak
    Published:5 Feb 2009
    7.5
    High

    CVE-2009-0446

    Last Modified: 25 Jan 2017

    SQL injection vulnerability in photo.php in WEBalbum 2.4b allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Mehmet Ince
    Published:5 Feb 2009
    7.5
    High

    CVE-2009-0445

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Dreampics Gallery Builder allows remote attackers to execute arbitrary SQL commands via the exhibition_id parameter in a gallery.viewPhotos action.

    Source:Mehmet Ince
    Published:5 Feb 2009
    7.5
    High

    CVE-2009-0444

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in GRBoard 1.8, when register_globals is enabled and magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) theme parameter to (a) 179_squarebox_pds_list/view.php, (b) 179_squarebox_minishop_expand/view.php, (c) 179_squarebox_gallery_list_pds/view.php, (d) 179_squarebox_gallery_list/view.php, (e) 179_squarebox_gallery/view.php, (f) 179_squarebox_board_swfupload/view.php, (g) 179_squarebox_board_expand/view.php, (h) 179_squarebox_board_basic_with_grcode/view.php, (i) 179_squarebox_board_basic/view.php, (j) 179_simplebar_pds_list/view.php, (k) 179_simplebar_notice/view.php, (l) 179_simplebar_gallery_list_pds/view.php, (m) 179_simplebar_gallery/view.php, and (n) 179_simplebar_basic/view.php in theme/; the (2) path parameter to (o) latest/sirini_gallery_latest/list.php; and the (3) grboard parameter to (p) include.php and (q) form_mail.php.

    Source:make0day
    Published:5 Feb 2009
    9.3
    Critical

    CVE-2009-0443

    Last Modified: 24 Jan 2017

    Stack-based buffer overflow in Elecard AVC HD PLAYER 5.5.90116 allows remote attackers to execute arbitrary code via an M3U file containing a long string in a URL.

    Source:AlpHaNiX
    Published:5 Feb 2009
    6.8
    Medium

    CVE-2009-0442

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in bbcode.php in PHPbbBook 1.3 and 1.3h allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the l parameter.

    Source:Osirys
    Published:5 Feb 2009
    6.8
    Medium

    CVE-2009-0441

    Last Modified: 31 Jan 2017

    PHP remote file inclusion vulnerability in skin_shop/standard/2_view_body/body_default.php in TECHNOTE 7.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the shop_this_skin_path parameter, a different vector than CVE-2008-4138.

    Source:make0day
    Published:5 Feb 2009
    7.5
    High

    CVE-2009-0431

    Last Modified: 8 Apr 2014

    SQL injection vulnerability in Default.asp in LinksPro Standard Edition allows remote attackers to execute arbitrary SQL commands via the OrderDirection parameter.

    Source:Pouya_Server
    Published:5 Feb 2009
    4.3
    Medium

    CVE-2009-0430

    Last Modified: 4 Jan 2017

    Multiple cross-site scripting (XSS) vulnerabilities in Active Bids allow remote attackers to inject arbitrary web script or HTML via the (1) search parameter to search.asp and the (2) URL parameter to tellafriend.asp.

    Source:Pouya_Server
    Published:5 Feb 2009
    7.5
    High

    CVE-2009-0429

    Last Modified: 4 Jan 2017

    Multiple SQL injection vulnerabilities in Active Bids allow remote attackers to execute arbitrary SQL commands via the (1) search parameter to search.asp, (2) SortDir parameter to auctionsended.asp, and the (3) catid parameter to wishlist.php.

    Source:Pouya_Server
    Published:5 Feb 2009
    7.5
    High

    CVE-2009-0428

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in CategoryManager/upload_image_category.asp in DMXReady Secure Document Library 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter.

    Source:ajann
    Published:5 Feb 2009
    7.5
    High

    CVE-2009-0427

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in CategoryManager/upload_image_category.asp in DMXReady Member Directory Manager 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter.

    Source:ajann
    Published:5 Feb 2009
    7.5
    High

    CVE-2009-0426

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in CategoryManager/upload_image_category.asp in DMXReady Classified Listings Manager 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter.

    Source:ajann
    Published:5 Feb 2009
    7.5
    High

    CVE-2009-0425

    Last Modified: 17 Jan 2017

    SQL injection vulnerability in index.php in Blue Eye CMS 1.0.0 and earlier allows remote attackers to execute arbitrary SQL commands via the clanek parameter.

    Source:darkjoker
    Published:5 Feb 2009
    7.5
    High

    CVE-2009-0423

    Last Modified: 23 Jan 2017

    Directory traversal vulnerability in index.php in Php Photo Album (PHPPA) 0.8 BETA allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the preview parameter.

    Source:Osirys
    Published:5 Feb 2009
    7.5
    High

    CVE-2009-0422

    Last Modified: 23 Apr 2026

    Dynamic variable evaluation vulnerability in lists/admin.php in phpList 2.10.8 and earlier, when register_globals is disabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the _SERVER[ConfigFile] parameter to admin/index.php.

    Source:BugReport.IR
    Published:5 Feb 2009
    7.5
    High

    CVE-2009-0421

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Eventing (com_eventing) 1.6.x component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php.

    Source:InjEctOr5
    Published:5 Feb 2009
    7.5
    High

    CVE-2009-0420

    Last Modified: 17 Jan 2017

    SQL injection vulnerability in the RD-Autos (com_rdautos) 1.5.5 Stable component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.

    Source:H!tm@N
    Published:5 Feb 2009
    10
    Critical

    CVE-2009-0410

    Last Modified: 23 Apr 2026

    Off-by-one error in the SMTP daemon in GroupWise Internet Agent (GWIA) in Novell GroupWise 6.5x, 7.0, 7.01, 7.02, 7.03, 7.03HP1a, and 8.0 allows remote attackers to execute arbitrary code via a long e-mail address in a malformed RCPT command, leading to a buffer overflow.

    Source:Praveen Darshanam
    Published:3 Feb 2009
    6.8
    Medium

    CVE-2009-0409

    Last Modified: 17 Jan 2017

    SQL injection vulnerability in offline_auth.php in Max.Blog 1.0.6 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the username parameter.

    Source:Salvatore Fresta
    Published:3 Feb 2009
    7.5
    High

    CVE-2009-0407

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin/login.php in PHP-CMS Project 1 allows remote attackers to execute arbitrary SQL commands via the username parameter.

    Source:darkjoker
    Published:3 Feb 2009
    7.5
    High

    CVE-2009-0406

    Last Modified: 23 Jan 2017

    SQL injection vulnerability in index.php in Community CMS 0.4 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:darkjoker
    Published:3 Feb 2009
    7.5
    High

    CVE-2009-0405

    Last Modified: 24 Jan 2017

    SQL injection vulnerability in articles.php in smartSite CMS 1.0 allows remote attackers to execute arbitrary SQL commands via the var parameter.

    Source:certaindeath
    Published:3 Feb 2009
    7.5
    High

    CVE-2009-0403

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin/authenticate.php in Chipmunk Blogger Script allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.

    Source:x0r
    Published:3 Feb 2009
    6.8
    Medium

    CVE-2009-0400

    Last Modified: 24 Jan 2017

    SQL injection vulnerability in blog.php in SocialEngine 3.06 trial allows remote attackers to execute arbitrary SQL commands via the category_id parameter.

    Source:snakespc
    Published:3 Feb 2009
    7.5
    High

    CVE-2009-0399

    Last Modified: 23 Apr 2026

    Chipmunk Blogger Script allows remote attackers to gain administrator privileges via a direct request to admin/reguser.php. NOTE: this is only a vulnerability when the administrator does not properly follow installation directions.

    Source:x0r
    Published:3 Feb 2009
    7.5
    High

    CVE-2009-0395

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the login feature in NetArt Media Car Portal 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.

    Source:Mehmet Ince
    Published:3 Feb 2009
    7.5
    High

    CVE-2009-0394

    Last Modified: 24 Jan 2017

    SQL injection vulnerability in login.php in Pre Lecture Exercises (PLEs) CMS 1.0 beta 4.2 allows remote attackers to execute arbitrary SQL commands via the school parameter.

    Source:darkjoker
    Published:3 Feb 2009
    3.5
    Low

    CVE-2009-0393

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in sysconf.cgi in Motorola Wimax modem CPEi300 allows remote authenticated users to inject arbitrary web script or HTML via the page parameter.

    Source:Usman Saeed
    Published:3 Feb 2009
    6.8
    Medium

    CVE-2009-0392

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in sysconf.cgi in Motorola Wimax modem CPEi300 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the page parameter.

    Source:Usman Saeed
    Published:3 Feb 2009
    7.2
    High

    CVE-2009-0390

    Last Modified: 23 Apr 2026

    Argument injection vulnerability in Enomaly Elastic Computing Platform (ECP), formerly Enomalism, before 2.1.1 allows local users to send signals to arbitrary processes by populating the /tmp/enomalism2.pid file with command-line arguments for the kill program.

    Source:Sam Johnston
    Published:2 Feb 2009
    9.3
    Critical

    CVE-2009-0389

    Last Modified: 23 Apr 2026

    Multiple insecure method vulnerabilities in the Web On Windows (WOW) ActiveX control in WOW ActiveX 2 allow remote attackers to (1) create and overwrite arbitrary files via the WriteIniFileString method, (2) execute arbitrary programs via the ShellExecute method, (3) read from the registry via unspecified vectors, and (4) write to the registry via unspecified vectors. NOTE: vectors 1 and 2 can be used together to execute arbitrary code.

    Source:Michael Brooks
    Published:2 Feb 2009
    10
    Critical

    CVE-2009-0388

    Last Modified: 23 Apr 2026

    Multiple integer signedness errors in (1) UltraVNC 1.0.2 and 1.0.5 and (2) TightVnc 1.3.9 allow remote VNC servers to cause a denial of service (heap corruption and application crash) or possibly execute arbitrary code via a large length value in a message, related to the (a) ClientConnection::CheckBufferSize and (b) ClientConnection::CheckFileZipBufferSize functions in ClientConnection.cpp.

    Source:desi
    Published:4 Feb 2009
    6.8
    Medium

    CVE-2009-0384

    Last Modified: 23 Jan 2017

    SQL injection vulnerability in autor.php in OwnRS CMS 1.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:nuclear
    Published:2 Feb 2009
    6.4
    Medium

    CVE-2009-0383

    Last Modified: 23 Apr 2026

    delete.php in Max.Blog 1.0.6 does not properly restrict access, which allows remote attackers to delete arbitrary blog posts via a direct request.

    Source:SirGod
    Published:2 Feb 2009
    7.5
    High

    CVE-2009-0381

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the BazaarBuilder Ecommerce Shopping Cart (com_prod) 5.0 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid parameter in a products action to index.php.

    Source:XaDoS
    Published:2 Feb 2009
    7.5
    High

    CVE-2009-0380

    Last Modified: 18 Jan 2017

    SQL injection vulnerability in the Sigsiu Online Business Index 2 (SOBI2, com_sobi2) RC 2.8.2 component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the bid parameter in a showbiz action to index.php, a different vector than CVE-2008-0607. NOTE: CVE disputes this issue, since neither "showbiz" nor "bid" appears in the source code for SOBI2

    Source:Br1ght D@rk
    Published:2 Feb 2009
    7.5
    High

    CVE-2009-0379

    Last Modified: 18 Jan 2017

    SQL injection vulnerability in the Prince Clan Chess Club (com_pcchess) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the game_id parameter in a showgame action to index.php, a different vector than CVE-2008-0761.

    Source:InjEctOr5
    Published:2 Feb 2009
    4.3
    Medium

    CVE-2009-0378

    Last Modified: 23 Jan 2017

    Cross-site scripting (XSS) vulnerability in index.php in the beamospetition (com_beamospetition) 1.0.12 component for Joomla! allows remote attackers to inject arbitrary web script or HTML via the pet parameter in a sign action.

    Source:vds_s
    Published:2 Feb 2009
    7.5
    High

    CVE-2009-0377

    Last Modified: 23 Jan 2017

    SQL injection vulnerability in the beamospetition (com_beamospetition) 1.0.12 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the mpid parameter in a sign action to index.php, a different vector than CVE-2008-3132.

    Source:vds_s
    Published:2 Feb 2009