258631
|
- |
|
activewebsoftwares
|
ewebquiz
|
Multiple SQL injection vulnerabilities in Active Web Softwares eWebquiz 8 allow remote attackers to execute arbitrary SQL commands via the QuizID parameter to (1) questions.asp, (2) importquestions.a…
|
CWE-89
SQL Injection
|
CVE-2009-4436
|
2017-08-17 10:31 |
2009-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258632
|
- |
|
activewebsoftwares
|
active_auction_house
|
Multiple SQL injection vulnerabilities in Active Auction House 3.6 allow remote attackers to execute arbitrary SQL commands via the (1) catid parameter to wishlist.asp and the (2) linkid parameter to…
|
CWE-89
SQL Injection
|
CVE-2009-4437
|
2017-08-17 10:31 |
2009-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258633
|
- |
|
ikemcg
|
phpinstantgallery
|
Cross-site scripting (XSS) vulnerability in admin.php in phpInstantGallery 1.1 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.
|
CWE-79
Cross-site Scripting
|
CVE-2009-4446
|
2017-08-17 10:31 |
2009-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258634
|
- |
|
jax_scripts
|
jax_guestbook
|
Jax Guestbook 3.5.0 allows remote attackers to bypass authentication and modify administrator settings via a direct request to admin/guestbook.admin.php.
|
CWE-287
Improper Authentication
|
CVE-2009-4447
|
2017-08-17 10:31 |
2009-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258635
|
- |
|
microsoft
|
internet_information_services
|
Microsoft Internet Information Services (IIS), when used in conjunction with unspecified third-party upload applications, allows remote attackers to create empty files with arbitrary extensions via a…
|
CWE-20
Improper Input Validation
|
CVE-2009-4445
|
2017-08-17 10:31 |
2009-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258636
|
- |
|
softcab
|
sound_converter_activex
|
Insecure method vulnerability in SoftCab Sound Converter ActiveX control (sndConverter.ocx) 1.2 allows remote attackers to create or overwrite arbitrary files via the SaveFormat method. NOTE: some o…
|
NVD-CWE-Other
|
CVE-2009-4453
|
2017-08-17 10:31 |
2009-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258637
|
- |
|
softcab
|
sound_converter_activex
|
Per: http://cwe.mitre.org/data/definitions/749.html
'CWE-749: Exposed Dangerous Method or Function'
|
NVD-CWE-Other
|
CVE-2009-4453
|
2017-08-17 10:31 |
2009-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258638
|
- |
|
freepbx
|
freepbx
|
Multiple cross-site scripting (XSS) vulnerabilities in FreePBX 2.5.2 and 2.6.0rc2, and possibly other versions, allow remote attackers to inject arbitrary web script or HTML via the (1) tech paramete…
|
CWE-79
Cross-site Scripting
|
CVE-2009-4458
|
2017-08-17 10:31 |
2009-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258639
|
- |
|
redmine
|
redmine
|
Redmine 0.8.7 and earlier uses the title tag before defining the character encoding in a meta tag, which allows remote attackers to conduct cross-site scripting (XSS) attacks and inject arbitrary scr…
|
CWE-79
Cross-site Scripting
|
CVE-2009-4459
|
2017-08-17 10:31 |
2009-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258640
|
- |
|
activewebsoftwares
|
active_business_directory
|
Cross-site scripting (XSS) vulnerability in searchadvance.asp in Active Business Directory 2 allows remote attackers to inject arbitrary web script or HTML via the search parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2009-4464
|
2017-08-17 10:31 |
2009-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|