260831
|
- |
|
datetopia
|
match_agency_biz
|
Multiple cross-site scripting (XSS) vulnerabilities in Match Agency BiZ 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) important parameter to edit_profile.php and (2) p…
|
CWE-79
Cross-site Scripting
|
CVE-2009-3359
|
2017-08-17 10:31 |
2009-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260832
|
- |
|
datemill
|
datemill
|
Multiple cross-site scripting (XSS) vulnerabilities in Datemill 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) return parameter to photo_view.php, and st parameter to (…
|
CWE-79
Cross-site Scripting
|
CVE-2009-3360
|
2017-08-17 10:31 |
2009-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260833
|
- |
|
ufku_bayburt
|
bueditor
|
Cross-site scripting (XSS) vulnerability in the BUEditor module 5.x before 5.x-1.2 and 6.x before 6.x-1.4, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via inpu…
|
CWE-79
Cross-site Scripting
|
CVE-2009-3363
|
2017-08-17 10:31 |
2009-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260834
|
- |
|
mozilla
|
bugzilla
|
Template.pm in Bugzilla 3.3.2 through 3.4.3 and 3.5 through 3.5.1 allows remote attackers to discover the alias of a private bug by reading the (1) Depends On or (2) Blocks field of a related bug.
|
CWE-200
Information Exposure
|
CVE-2009-3386
|
2017-08-17 10:31 |
2009-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260835
|
- |
|
sun
|
opensolaris solaris
|
Unspecified vulnerability in xscreensaver in Sun Solaris 10, and OpenSolaris before snv_112, when Xorg or Xnewt is used and RandR is enabled, allows physically proximate attackers to read a locked sc…
|
NVD-CWE-noinfo
|
CVE-2009-3432
|
2017-08-17 10:31 |
2009-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260836
|
- |
|
sun
|
cluster
|
Unspecified vulnerability in clsetup in the configuration utility in Sun Solaris Cluster 3.2 allows local users to gain privileges via unknown vectors.
|
NVD-CWE-noinfo
|
CVE-2009-3433
|
2017-08-17 10:31 |
2009-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260837
|
- |
|
onestopjoomla
|
com_tupinambis
|
SQL injection vulnerability in the Tupinambis (com_tupinambis) component 1.0 for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the proyecto parameter in a verproyect…
|
CWE-89
SQL Injection
|
CVE-2009-3434
|
2017-08-17 10:31 |
2009-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260838
|
- |
|
moshe_weitzman
|
devel
|
Cross-site scripting (XSS) vulnerability in the variable editor in the Devel module 5.x before 5.x-1.2 and 6.x before 6.x-1.18, a module for Drupal, allows remote attackers to inject arbitrary web sc…
|
CWE-79
Cross-site Scripting
|
CVE-2009-3435
|
2017-08-17 10:31 |
2009-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260839
|
- |
|
maxwebportal
|
maxwebportal
|
Multiple SQL injection vulnerabilities in forum.asp in MaxWebPortal allow remote attackers to execute arbitrary SQL commands via the (1) FORUM_ID or (2) CAT_ID parameter. NOTE: this might overlap CV…
|
CWE-89
SQL Injection
|
CVE-2009-3436
|
2017-08-17 10:31 |
2009-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260840
|
- |
|
witchakorn_kamolpornwijit
|
com_facebook
|
SQL injection vulnerability in the JoomlaFacebook (com_facebook) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a student action to index.php.
|
CWE-89
SQL Injection
|
CVE-2009-3438
|
2017-08-17 10:31 |
2009-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|