262801
|
- |
|
mischa_heissmann
|
no_indexed_search
|
SQL injection vulnerability in the No indexed Search (no_indexed_search) extension 0.2.0 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unknown vectors.
|
CWE-89
SQL Injection
|
CVE-2009-4341
|
2017-08-17 10:31 |
2009-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262802
|
- |
|
melvin_mach
|
jobexchange
|
SQL injection vulnerability in the Job Exchange (jobexchange) extension 0.0.3 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unknown vectors.
|
CWE-89
SQL Injection
|
CVE-2009-4342
|
2017-08-17 10:31 |
2009-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262803
|
- |
|
dominic_eckart
|
trainincdb
|
Cross-site scripting (XSS) vulnerability in the Training Company Database (trainincdb) extension 0.4.7 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2009-4343
|
2017-08-17 10:31 |
2009-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262804
|
- |
|
tobias_sommer
|
zid_linklist
|
Cross-site scripting (XSS) vulnerability in the ZID Linkliste (zid_linklist) extension 1.0.0 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2009-4344
|
2017-08-17 10:31 |
2009-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262805
|
- |
|
jonas_renggli
|
vshoutbox
|
Cross-site scripting (XSS) vulnerability in the vShoutbox (vshoutbox) extension 0.0.1 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2009-4345
|
2017-08-17 10:31 |
2009-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262806
|
- |
|
phpwebscripts
|
link_up_gold
|
Cross-site request forgery (CSRF) vulnerability in administration/administrators.php in Link Up Gold 5.0 allows remote attackers to hijack the authentication of administrators for requests that creat…
|
CWE-352
Origin Validation Error
|
CVE-2009-4349
|
2017-08-17 10:31 |
2009-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262807
|
- |
|
transware
|
active_mail_2003
|
Multiple cross-site scripting (XSS) vulnerabilities in TransWARE Active! mail 2003 build 2003.0139.0871 and earlier, and possibly other versions before 2003.0139.0939, allow remote attackers to injec…
|
CWE-79
Cross-site Scripting
|
CVE-2009-4352
|
2017-08-17 10:31 |
2009-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262808
|
- |
|
transware
|
active\!_mail
|
The Mobile Edition of TransWARE Active! mail 2003 build 2003.0139.0871 and earlier, and possibly other versions before 2003.0139.0911, does not remove the session ID in a Referer URL, which allows re…
|
NVD-CWE-Other
|
CVE-2009-4353
|
2017-08-17 10:31 |
2009-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262809
|
- |
|
transware
|
active\!_mail
|
TransWARE Active! mail 2003 build 2003.0139.0871 and earlier does not properly secure the session ID in a session cookie, which allows remote attackers to hijack web sessions, probably related to the…
|
CWE-255
Credentials Management
|
CVE-2009-4354
|
2017-08-17 10:31 |
2009-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262810
|
- |
|
marc-andre_lanciault
|
smartmedia
|
Cross-site scripting (XSS) vulnerability in folder.php in the SmartMedia 0.85 Beta module for XOOPS allows remote attackers to inject arbitrary web script or HTML via the categoryid parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2009-4359
|
2017-08-17 10:31 |
2009-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|