258321
|
- |
|
simplog
|
simplog
|
Cross-site request forgery (CSRF) vulnerability in user.php in Simplog 0.9.3.2, and possibly earlier, allows remote attackers to hijack the authentication of administrators and users for requests tha…
|
CWE-352
Origin Validation Error
|
CVE-2009-4092
|
2017-08-17 10:31 |
2009-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258322
|
- |
|
simplog
|
simplog
|
Multiple cross-site scripting (XSS) vulnerabilities in comments.php in Simplog 0.9.3.2, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) cname (Name) or…
|
CWE-79
Cross-site Scripting
|
CVE-2009-4093
|
2017-08-17 10:31 |
2009-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258323
|
- |
|
companionway
|
myphile
|
myPhile 1.2.1 allows remote attackers to bypass authentication via an empty password. NOTE: some of these details are obtained from third party information.
|
CWE-287
Improper Authentication
|
CVE-2009-4095
|
2017-08-17 10:31 |
2009-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258324
|
- |
|
malsmith
|
serenity_audio_player
|
Stack-based buffer overflow in the MplayInputFile function in Serenity Audio Player 3.2.3 and earlier allows remote attackers to execute arbitrary code via a long URL in an M3U file. NOTE: some of t…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-4097
|
2017-08-17 10:31 |
2009-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258325
|
- |
|
g4j.laoneo
|
com_gcalendar
|
SQL injection vulnerability in the Google Calendar GCalendar (com_gcalendar) component 1.1.2, 2.1.4, and possibly earlier versions for Joomla! allows remote attackers to execute arbitrary SQL command…
|
CWE-89
SQL Injection
|
CVE-2009-4099
|
2017-08-17 10:31 |
2009-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258326
|
- |
|
yoono
|
yoono
|
Yoono extension before 6.1.1 for Firefox performs certain operations with chrome privileges, which allows user-assisted remote attackers to execute arbitrary commands and perform cross-domain scripti…
|
CWE-20
Improper Input Validation
|
CVE-2009-4100
|
2017-08-17 10:31 |
2009-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258327
|
- |
|
yoono
|
yoono
|
Per info from the following advisory:
http://www.net-security.org/secworld.php?id=8527
Raised the score to CIA:complete
NVD received information from Yoono development team on December 4,…
|
CWE-20
Improper Input Validation
|
CVE-2009-4100
|
2017-08-17 10:31 |
2009-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258328
|
- |
|
yoono
|
yoono
|
NVD received information from Yoono development team on December 4, 2009 that the fixed version is in fact 6.1.1. A patch can be found at the following URL:
https://addons.mozilla.org/en-US/firef…
|
CWE-20
Improper Input Validation
|
CVE-2009-4100
|
2017-08-17 10:31 |
2009-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258329
|
- |
|
didier_ernotte
|
inforss
|
infoRSS 1.1.4.2 and earlier extension for Firefox performs certain operations with chrome privileges, which allows remote attackers to execute arbitrary commands and perform cross-domain scripting at…
|
CWE-20
Improper Input Validation
|
CVE-2009-4101
|
2017-08-17 10:31 |
2009-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258330
|
- |
|
didier_ernotte
|
inforss
|
Per information from the following advisory:
http://www.net-security.org/secworld.php?id=8527
raised the score to CIA:complete since this vulnerability gives attacker the full access to the compute…
|
CWE-20
Improper Input Validation
|
CVE-2009-4101
|
2017-08-17 10:31 |
2009-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|