257211
|
- |
|
kreotek
|
phpbms
|
Multiple cross-site scripting (XSS) vulnerabilities in phpBMS 0.96 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) index.php and (2) modules\base\myaccount.php;…
|
CWE-79
Cross-site Scripting
|
CVE-2009-3755
|
2017-09-19 10:29 |
2009-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257212
|
- |
|
kreotek
|
phpbms
|
phpBMS 0.96 allows remote attackers to obtain sensitive information via a direct request to (1) footer.php, (2) header.php, (3) the show action in advancedsearch.php, and (4) choicelist.php, which re…
|
CWE-200
Information Exposure
|
CVE-2009-3756
|
2017-09-19 10:29 |
2009-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257213
|
- |
|
citrix
|
xencenterweb
|
Multiple cross-site scripting (XSS) vulnerabilities in sample code in the XenServer Resource Kit in Citrix XenCenterWeb allow remote attackers to inject arbitrary web script or HTML via the (1) usern…
|
CWE-79
Cross-site Scripting
|
CVE-2009-3757
|
2017-09-19 10:29 |
2009-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257214
|
- |
|
citrix
|
xencenterweb
|
SQL injection vulnerability in login.php in sample code in the XenServer Resource Kit in Citrix XenCenterWeb allows remote attackers to execute arbitrary SQL commands via the username parameter. NOT…
|
CWE-89
SQL Injection
|
CVE-2009-3758
|
2017-09-19 10:29 |
2009-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257215
|
- |
|
citrix
|
xencenterweb
|
Static code injection vulnerability in config/writeconfig.php in the sample code in the XenServer Resource Kit in Citrix XenCenterWeb allows remote attackers to inject arbitrary PHP code into include…
|
CWE-94
Code Injection
|
CVE-2009-3760
|
2017-09-19 10:29 |
2009-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257216
|
- |
|
adobe
|
adobe_air flash_player
|
Adobe Flash Player 10.x before 10.0.42.34 and Adobe AIR before 1.5.3 might allow attackers to execute arbitrary code via unspecified vectors that trigger memory corruption.
|
CWE-399
Resource Management Errors
|
CVE-2009-3797
|
2017-09-19 10:29 |
2009-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257217
|
- |
|
mixvibes
|
mixvibes
|
Stack-based buffer overflow in MixVibes 7.043 Pro allows remote attackers to cause a denial of service (crash) via a long string in a .vib file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-3807
|
2017-09-19 10:29 |
2009-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257218
|
- |
|
kramware
|
mixsense_dj_studio
|
MixSense DJ Studio 1.0.0.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long string in an .mp3 playlist file.
|
NVD-CWE-Other
|
CVE-2009-3808
|
2017-09-19 10:29 |
2009-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257219
|
- |
|
acoustica
|
mp3_audio_mixer
|
Acoustica MP3 Audio Mixer 1.0 and possibly 2.471 allows remote attackers to cause a denial of service (crash) via a long string in a .sgp playlist file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-3809
|
2017-09-19 10:29 |
2009-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257220
|
- |
|
acoustica
|
mp3_audio_mixer
|
Heap-based buffer overflow in Acoustica MP3 Audio Mixer 2.471 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long string in a .M3U playlist file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-3810
|
2017-09-19 10:29 |
2009-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|