262811
|
- |
|
handcoders
|
content_module
|
SQL injection vulnerability in modules/content/index.php in the Content module 0.5 for XOOPS allows remote attackers to inject arbitrary web script or HTML via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2009-4360
|
2017-08-17 10:31 |
2009-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262812
|
- |
|
scriptsez
|
ez_blog
|
Cross-site scripting (XSS) vulnerability in index.php in ScriptsEz Ez Blog allows remote attackers to inject arbitrary web script or HTML via the cname parameter, related to the act and id parameters…
|
CWE-79
Cross-site Scripting
|
CVE-2009-4364
|
2017-08-17 10:31 |
2009-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262813
|
- |
|
scriptsez
|
ez_blog
|
Multiple cross-site request forgery (CSRF) vulnerabilities in admin.php in ScriptsEz Ez Blog 1.0 allow remote attackers to hijack the authentication of administrators for requests that (1) add a blog…
|
CWE-352
Origin Validation Error
|
CVE-2009-4365
|
2017-08-17 10:31 |
2009-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262814
|
- |
|
scriptsez
|
ez_blog
|
Cross-site scripting (XSS) vulnerability in index.php in ScriptsEz Ez Blog 1.0 allows remote attackers to inject arbitrary web script or HTML via the yr parameter in a bmonth action.
|
CWE-79
Cross-site Scripting
|
CVE-2009-4366
|
2017-08-17 10:31 |
2009-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262815
|
- |
|
merethis
|
centreon
|
Multiple unspecified vulnerabilities in Centreon before 2.1.4 have unknown impact and attack vectors in the (1) ping tool, (2) traceroute tool, and (3) ldap import, possibly related to improper authe…
|
NVD-CWE-noinfo
|
CVE-2009-4368
|
2017-08-17 10:31 |
2009-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262816
|
- |
|
drupal
|
drupal
|
Cross-site scripting (XSS) vulnerability in the Contact module (modules/contact/contact.admin.inc or modules/contact/contact.module) in Drupal Core 5.x before 5.21 and 6.x before 6.15 allows remote a…
|
CWE-79
Cross-site Scripting
|
CVE-2009-4369
|
2017-08-17 10:31 |
2009-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262817
|
- |
|
drupal
|
drupal
|
Cross-site scripting (XSS) vulnerability in the Menu module (modules/menu/menu.admin.inc) in Drupal Core 6.x before 6.15 allows remote authenticated users with permissions to create new menus to inje…
|
CWE-79
Cross-site Scripting
|
CVE-2009-4370
|
2017-08-17 10:31 |
2009-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262818
|
- |
|
drupal
|
drupal
|
Cross-site scripting (XSS) vulnerability in the Locale module (modules/locale/locale.module) in Drupal Core 6.14, and possibly other versions including 6.15, allows remote authenticated users with "a…
|
CWE-79
Cross-site Scripting
|
CVE-2009-4371
|
2017-08-17 10:31 |
2009-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262819
|
- |
|
alienvault
|
open_source_security_information_management
|
AlienVault Open Source Security Information Management (OSSIM) 2.1.5, and possibly other versions before 2.1.5-4, allows remote attackers to execute arbitrary commands via shell metacharacters in the…
|
CWE-20
Improper Input Validation
|
CVE-2009-4372
|
2017-08-17 10:31 |
2009-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262820
|
- |
|
texmedia
|
million_pixel_script
|
Cross-site scripting (XSS) vulnerability in index.php in texmedia Million Pixel Script 3 allows remote attackers to inject arbitrary web script or HTML via the pa parameter. NOTE: some of these deta…
|
CWE-79
Cross-site Scripting
|
CVE-2009-4381
|
2017-08-17 10:31 |
2009-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|