257461
|
- |
|
transware
|
active\!_mail
|
The Mobile Edition of TransWARE Active! mail 2003 build 2003.0139.0871 and earlier, and possibly other versions before 2003.0139.0911, does not remove the session ID in a Referer URL, which allows re…
|
NVD-CWE-Other
|
CVE-2009-4353
|
2017-08-17 10:31 |
2009-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257462
|
- |
|
transware
|
active\!_mail
|
TransWARE Active! mail 2003 build 2003.0139.0871 and earlier does not properly secure the session ID in a session cookie, which allows remote attackers to hijack web sessions, probably related to the…
|
CWE-255
Credentials Management
|
CVE-2009-4354
|
2017-08-17 10:31 |
2009-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257463
|
- |
|
marc-andre_lanciault
|
smartmedia
|
Cross-site scripting (XSS) vulnerability in folder.php in the SmartMedia 0.85 Beta module for XOOPS allows remote attackers to inject arbitrary web script or HTML via the categoryid parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2009-4359
|
2017-08-17 10:31 |
2009-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257464
|
- |
|
handcoders
|
content_module
|
SQL injection vulnerability in modules/content/index.php in the Content module 0.5 for XOOPS allows remote attackers to inject arbitrary web script or HTML via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2009-4360
|
2017-08-17 10:31 |
2009-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257465
|
- |
|
scriptsez
|
ez_blog
|
Cross-site scripting (XSS) vulnerability in index.php in ScriptsEz Ez Blog allows remote attackers to inject arbitrary web script or HTML via the cname parameter, related to the act and id parameters…
|
CWE-79
Cross-site Scripting
|
CVE-2009-4364
|
2017-08-17 10:31 |
2009-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257466
|
- |
|
scriptsez
|
ez_blog
|
Multiple cross-site request forgery (CSRF) vulnerabilities in admin.php in ScriptsEz Ez Blog 1.0 allow remote attackers to hijack the authentication of administrators for requests that (1) add a blog…
|
CWE-352
Origin Validation Error
|
CVE-2009-4365
|
2017-08-17 10:31 |
2009-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257467
|
- |
|
scriptsez
|
ez_blog
|
Cross-site scripting (XSS) vulnerability in index.php in ScriptsEz Ez Blog 1.0 allows remote attackers to inject arbitrary web script or HTML via the yr parameter in a bmonth action.
|
CWE-79
Cross-site Scripting
|
CVE-2009-4366
|
2017-08-17 10:31 |
2009-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257468
|
- |
|
merethis
|
centreon
|
Multiple unspecified vulnerabilities in Centreon before 2.1.4 have unknown impact and attack vectors in the (1) ping tool, (2) traceroute tool, and (3) ldap import, possibly related to improper authe…
|
NVD-CWE-noinfo
|
CVE-2009-4368
|
2017-08-17 10:31 |
2009-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257469
|
- |
|
drupal
|
drupal
|
Cross-site scripting (XSS) vulnerability in the Contact module (modules/contact/contact.admin.inc or modules/contact/contact.module) in Drupal Core 5.x before 5.21 and 6.x before 6.15 allows remote a…
|
CWE-79
Cross-site Scripting
|
CVE-2009-4369
|
2017-08-17 10:31 |
2009-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257470
|
- |
|
drupal
|
drupal
|
Cross-site scripting (XSS) vulnerability in the Menu module (modules/menu/menu.admin.inc) in Drupal Core 6.x before 6.15 allows remote authenticated users with permissions to create new menus to inje…
|
CWE-79
Cross-site Scripting
|
CVE-2009-4370
|
2017-08-17 10:31 |
2009-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|