Products: 4
    Vulnerabilities: 5
    Known Exploited: 0
    1
    Critical Level Threats
    0
    High Level Threats
    4
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2009-3493

    Multiple cross-site scripting (XSS) vulnerabilities in Zenas PaoBacheca Guestbook 2.1 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) scrivi.php and (2) index.php.

    Last Modified: Apr 23, 2026
    Published: Sep 30, 2009

    CVE-2009-3422

    login.php in Zenas PaoLiber 1.1, when register_globals is enabled, allows remote attackers to bypass authentication and gain administrative access by setting the login_ok parameter to 1.

    Last Modified: Apr 23, 2026
    Published: Sep 25, 2009

    CVE-2009-3423

    login.php in Zenas PaoLink 1.0, when register_globals is enabled, allows remote attackers to bypass authentication and gain administrative access by setting the login_ok parameter to 1.

    Last Modified: Apr 23, 2026
    Published: Sep 25, 2009

    CVE-2009-3421

    login.php in Zenas PaoBacheca Guestbook 2.1, when register_globals is enabled, allows remote attackers to bypass authentication and gain administrative access by setting the login_ok parameter to 1.

    Last Modified: Apr 23, 2026
    Published: Sep 25, 2009

    CVE-2009-3320

    Cross-site scripting (XSS) vulnerability in scrivi.php in Zenas PaoLink (aka Pao-Link) 1.0 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.

    Last Modified: Apr 23, 2026
    Published: Sep 23, 2009
    Items Per Page