257421
|
- |
|
gnu
|
libtool
|
ltdl.c in libltdl in GNU Libtool 1.5.x, and 2.2.6 before 2.2.6b, as used in Ham Radio Control Libraries, Q, and possibly other products, attempts to open a .la file in the current working directory, …
|
NVD-CWE-Other
|
CVE-2009-3736
|
2017-09-19 10:29 |
2009-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257422
|
- |
|
sun
|
solaris
|
XScreenSaver in Sun Solaris 10, when the accessibility feature is enabled, allows physically proximate attackers to obtain sensitive information by reading popup windows, which are displayed even whe…
|
CWE-16
Configuration
|
CVE-2009-3746
|
2017-09-19 10:29 |
2009-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257423
|
- |
|
santostefano_giovanni
|
toylog
|
SQL injection vulnerability in read.php in ToyLog 0.1 allows remote attackers to execute arbitrary SQL commands via the idm parameter.
|
CWE-89
SQL Injection
|
CVE-2009-3750
|
2017-09-19 10:29 |
2009-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257424
|
- |
|
opial
|
opial
|
Cross-site scripting (XSS) vulnerability in home.php in Opial 1.0 allows remote attackers to inject arbitrary web script or HTML via the genres_parent parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2009-3751
|
2017-09-19 10:29 |
2009-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257425
|
- |
|
opial
|
opial
|
SQL injection vulnerability in home.php in Opial 1.0 allows remote attackers to execute arbitrary SQL commands via the genres_parent parameter.
|
CWE-89
SQL Injection
|
CVE-2009-3752
|
2017-09-19 10:29 |
2009-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257426
|
- |
|
opial
|
opial
|
Unrestricted file upload vulnerability in Opial 1.0 allows remote attackers to execute arbitrary code by uploading a file with an executable extension as a User Image, then accessing it via a request…
|
CWE-20
Improper Input Validation
|
CVE-2009-3753
|
2017-09-19 10:29 |
2009-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257427
|
- |
|
kreotek
|
phpbms
|
Multiple SQL injection vulnerabilities in phpBMS 0.96 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to modules/bms/invoices_discount_ajax.php, (2) f parameter to d…
|
CWE-89
SQL Injection
|
CVE-2009-3754
|
2017-09-19 10:29 |
2009-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257428
|
- |
|
kreotek
|
phpbms
|
Multiple cross-site scripting (XSS) vulnerabilities in phpBMS 0.96 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) index.php and (2) modules\base\myaccount.php;…
|
CWE-79
Cross-site Scripting
|
CVE-2009-3755
|
2017-09-19 10:29 |
2009-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257429
|
- |
|
kreotek
|
phpbms
|
phpBMS 0.96 allows remote attackers to obtain sensitive information via a direct request to (1) footer.php, (2) header.php, (3) the show action in advancedsearch.php, and (4) choicelist.php, which re…
|
CWE-200
Information Exposure
|
CVE-2009-3756
|
2017-09-19 10:29 |
2009-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257430
|
- |
|
citrix
|
xencenterweb
|
Multiple cross-site scripting (XSS) vulnerabilities in sample code in the XenServer Resource Kit in Citrix XenCenterWeb allow remote attackers to inject arbitrary web script or HTML via the (1) usern…
|
CWE-79
Cross-site Scripting
|
CVE-2009-3757
|
2017-09-19 10:29 |
2009-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|