267611
|
- |
|
sun
|
java_system_portal_server
|
Multiple cross-site scripting (XSS) vulnerabilities in the Gateway component in Sun Java System Portal Server 6.3.1, 7.1, and 7.2 allow remote attackers to inject arbitrary web script or HTML via uns…
|
CWE-79
Cross-site Scripting
|
CVE-2009-4187
|
2009-12-4 14:00 |
2009-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267612
|
- |
|
hp
|
operations_dashboard
|
HP Operations Dashboard has a default password of j2deployer for the j2deployer account, which allows remote attackers to execute arbitrary code via a session that uses the manager role to conduct un…
|
CWE-255
Credentials Management
|
CVE-2009-4188
|
2009-12-4 14:00 |
2009-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267613
|
- |
|
hp
|
operations_manager
|
HP Operations Manager has a default password of OvW*busr1 for the ovwebusr account, which allows remote attackers to execute arbitrary code via a session that uses the manager role to conduct unrestr…
|
CWE-255
Credentials Management
|
CVE-2009-4189
|
2009-12-4 14:00 |
2009-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267614
|
- |
|
sun
|
opensolaris
|
Unspecified vulnerability in the kernel in Sun OpenSolaris 2009.06 allows remote attackers to cause a denial of service (panic) via unknown vectors, as demonstrated by the vd_solaris2 module in VulnD…
|
NVD-CWE-noinfo
|
CVE-2009-4190
|
2009-12-4 14:00 |
2009-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267615
|
- |
|
interspire
|
knowledge_manager
|
Directory traversal vulnerability in dialog/file_manager.php in Interspire Knowledge Manager 5 allows remote attackers to read arbitrary files via a .. (dot dot) in the p parameter. NOTE: the proven…
|
CWE-22
Path Traversal
|
CVE-2009-4192
|
2009-12-4 14:00 |
2009-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267616
|
- |
|
wikipedia
|
wikipedia_toolbar
|
Unspecified vulnerability in Wikipedia Toolbar extension before 0.5.9.2 for Firefox allows user-assisted remote attackers to execute arbitrary JavaScript with Chrome privileges via vectors involving …
|
CWE-94
Code Injection
|
CVE-2009-4127
|
2009-12-3 14:00 |
2009-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267617
|
- |
|
ibm
|
websphere_portal
|
Unspecified vulnerability in the XMLAccess component in IBM WebSphere Portal 6.1.x before 6.1.0.3 has unknown impact and attack vectors, related to the work directory.
|
NVD-CWE-noinfo
|
CVE-2009-4153
|
2009-12-3 14:00 |
2009-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267618
|
- |
|
elxis
|
elxis_cms
|
Directory traversal vulnerability in includes/feedcreator.class.php in Elxis CMS allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter.
|
CWE-22
Path Traversal
|
CVE-2009-4154
|
2009-12-3 14:00 |
2009-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267619
|
- |
|
ciamos
|
ciamos_cms
|
PHP remote file inclusion vulnerability in modules/pms/index.php in Ciamos CMS 0.9.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the module_path parameter.
|
CWE-94
Code Injection
|
CVE-2009-4156
|
2009-12-3 14:00 |
2009-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267620
|
- |
|
mario_matzulla
|
cal
|
SQL injection vulnerability in the Calendar Base (cal) extension before 1.2.1 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
|
CWE-89
SQL Injection
|
CVE-2009-4158
|
2009-12-3 14:00 |
2009-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|