258211
|
- |
|
freewebscriptz
|
freelancers
|
Multiple cross-site scripting (XSS) vulnerabilities in Freelancers 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to placebid.php and (2) jobid parameter t…
|
CWE-79
Cross-site Scripting
|
CVE-2009-3593
|
2017-08-17 10:31 |
2009-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258212
|
- |
|
blob
|
blog_system
|
Cross-site scripting (XSS) vulnerability in bpost.php in BLOB Blog System before 1.2 allows remote attackers to inject arbitrary web script or HTML via the postid parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2009-3594
|
2017-08-17 10:31 |
2009-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258213
|
- |
|
ecardmax.com
|
formxp
|
Cross-site scripting (XSS) vulnerability in survey_result.php in eCardMAX FormXP 2007 allows remote attackers to inject arbitrary web script or HTML via the sid parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2009-3598
|
2017-08-17 10:31 |
2009-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258214
|
- |
|
freewebscriptz
|
hubscript
|
Cross-site scripting (XSS) vulnerability in single_winner1.php in HUBScript 1.0 allows remote attackers to inject arbitrary web script or HTML via the bid_id parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2009-3599
|
2017-08-17 10:31 |
2009-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258215
|
- |
|
freewebscriptz
|
hubscript
|
HUBScript 1.0 allows remote attackers to obtain configuration information via a direct request to manage/phpinfo.php, which calls the phpinfo function.
|
CWE-200
Information Exposure
|
CVE-2009-3600
|
2017-08-17 10:31 |
2009-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258216
|
- |
|
scriptsez
|
ultimate_poll
|
Cross-site scripting (XSS) vulnerability in demo_page.php in Scriptsez Ultimate Poll allows remote attackers to inject arbitrary web script or HTML via the clr parameter in a vote action.
|
CWE-79
Cross-site Scripting
|
CVE-2009-3601
|
2017-08-17 10:31 |
2009-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258217
|
- |
|
nlnetlabs
|
unbound
|
Unbound before 1.3.4 does not properly verify signatures for NSEC3 records, which allows remote attackers to cause secure delegations to be downgraded via DNS spoofing or other DNS-related attacks in…
|
CWE-310
Cryptographic Issues
|
CVE-2009-3602
|
2017-08-17 10:31 |
2009-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258218
|
- |
|
perl
|
perl
|
Perl 5.10.1 allows context-dependent attackers to cause a denial of service (application crash) via a UTF-8 character with a large, invalid codepoint, which is not properly handled during a regular-e…
|
NVD-CWE-Other
|
CVE-2009-3626
|
2017-08-17 10:31 |
2009-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258219
|
- |
|
derrick_oswald
|
html-parser
|
The decode_entities function in util.c in HTML-Parser before 3.63 allows context-dependent attackers to cause a denial of service (infinite loop) via an incomplete SGML numeric character reference, w…
|
CWE-20
Improper Input Validation
|
CVE-2009-3627
|
2017-08-17 10:31 |
2009-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258220
|
- |
|
typo3
|
typo3
|
The Backend subcomponent in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2 allows remote authenticated users to determine an encryption key via crafted …
|
CWE-200
Information Exposure
|
CVE-2009-3628
|
2017-08-17 10:31 |
2009-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|