258151
|
- |
|
ibm
|
websphere_application_server
|
The Servlet Engine/Web Container component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.37 does not properly implement security constraints on the (1) doGet and (2) doTrace methods, w…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-3106
|
2017-08-17 10:31 |
2009-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258152
|
- |
|
chris_shattuck
|
ajaxtable
|
Cross-site scripting (XSS) vulnerability in the Ajax Table module 5.x for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2009-3121
|
2017-08-17 10:31 |
2009-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258153
|
- |
|
chris_shattuck
|
ajaxtable
|
The Ajax Table module 5.x for Drupal does not perform access control, which allows remote attackers to delete arbitrary users and nodes via unspecified vectors.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-3122
|
2017-08-17 10:31 |
2009-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258154
|
- |
|
visavi
|
wap-motor
|
Directory traversal vulnerability in gallery/gallery.php in Wap-Motor before 18.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the image parameter.
|
CWE-22
Path Traversal
|
CVE-2009-3123
|
2017-08-17 10:31 |
2009-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258155
|
- |
|
articlefriend
|
articlefriend_script
|
Cross-site scripting (XSS) vulnerability in search_advance.php in ArticleFriend Script allows remote attackers to inject arbitrary web script or HTML via the SearchWd parameter. NOTE: the provenance…
|
CWE-79
Cross-site Scripting
|
CVE-2009-3146
|
2017-08-17 10:31 |
2009-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258156
|
- |
|
nt
|
bbs_e-market
|
Multiple cross-site scripting (XSS) vulnerabilities in becommunity/community/index.php in NTSOFT BBS E-Market Professional allow remote attackers to inject arbitrary web script or HTML via the (1) pa…
|
CWE-79
Cross-site Scripting
|
CVE-2009-3152
|
2017-08-17 10:31 |
2009-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258157
|
- |
|
x10media
|
mp3_search_engine
|
Multiple cross-site scripting (XSS) vulnerabilities in x10 MP3 Search engine 1.6.5 allow remote attackers to inject arbitrary web script or HTML via the (1) pic_id parameter to includes/video_ad.php,…
|
CWE-79
Cross-site Scripting
|
CVE-2009-3153
|
2017-08-17 10:31 |
2009-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258158
|
- |
|
sun
|
opensolaris solaris
|
Heap-based buffer overflow in w in Sun Solaris 8 through 10, and OpenSolaris before snv_124, allows local users to gain privileges via unspecified vectors.
|
NVD-CWE-noinfo CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-3183
|
2017-08-17 10:31 |
2009-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258159
|
- |
|
uloki
|
uloki_php_forum
|
Cross-site scripting (XSS) vulnerability in search.php in ULoKI PHP Forum 2.1 allows remote attackers to inject arbitrary web script or HTML via the term parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2009-3202
|
2017-08-17 10:31 |
2009-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258160
|
- |
|
ajsquare
|
aj_auction_pro-oopd
|
SQL injection vulnerability in store.php in AJ Auction Pro OOPD 2.x allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2009-3203
|
2017-08-17 10:31 |
2009-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|