258421
|
- |
|
softcab
|
sound_converter_activex
|
Per: http://cwe.mitre.org/data/definitions/749.html
'CWE-749: Exposed Dangerous Method or Function'
|
NVD-CWE-Other
|
CVE-2009-4453
|
2017-08-17 10:31 |
2009-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258422
|
- |
|
freepbx
|
freepbx
|
Multiple cross-site scripting (XSS) vulnerabilities in FreePBX 2.5.2 and 2.6.0rc2, and possibly other versions, allow remote attackers to inject arbitrary web script or HTML via the (1) tech paramete…
|
CWE-79
Cross-site Scripting
|
CVE-2009-4458
|
2017-08-17 10:31 |
2009-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258423
|
- |
|
redmine
|
redmine
|
Redmine 0.8.7 and earlier uses the title tag before defining the character encoding in a meta tag, which allows remote attackers to conduct cross-site scripting (XSS) attacks and inject arbitrary scr…
|
CWE-79
Cross-site Scripting
|
CVE-2009-4459
|
2017-08-17 10:31 |
2009-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258424
|
- |
|
activewebsoftwares
|
active_business_directory
|
Cross-site scripting (XSS) vulnerability in searchadvance.asp in Active Business Directory 2 allows remote attackers to inject arbitrary web script or HTML via the search parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2009-4464
|
2017-08-17 10:31 |
2009-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258425
|
- |
|
deluxebb
|
deluxebb
|
DeluxeBB 1.3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain user and configuration information, log data, and gain administr…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-4465
|
2017-08-17 10:31 |
2009-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258426
|
- |
|
deluxebb
|
deluxebb
|
DeluxeBB 1.3 allows remote attackers to obtain sensitive information via a crafted page parameter to misc.php, which reveals the installation path in an error message. NOTE: this issue might be resu…
|
CWE-200
Information Exposure
|
CVE-2009-4466
|
2017-08-17 10:31 |
2009-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258427
|
- |
|
deluxebb
|
deluxebb
|
misc.php in DeluxeBB 1.3 allows remote attackers to register accounts without a valid email address via a valemail action with the valmem set to a pre-assigned user ID, which is visible from a member…
|
CWE-20
Improper Input Validation
|
CVE-2009-4467
|
2017-08-17 10:31 |
2009-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258428
|
- |
|
deluxebb
|
deluxebb
|
Cross-site scripting (XSS) vulnerability in misc.php in DeluxeBB 1.3 allows remote attackers to inject arbitrary web script or HTML via the page parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2009-4468
|
2017-08-17 10:31 |
2009-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258429
|
- |
|
giombetti
|
phppowercards
|
Multiple cross-site scripting (XSS) vulnerabilities in pagenumber.inc.php in phpPowerCards 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO, the (2) archiv para…
|
CWE-79
Cross-site Scripting
|
CVE-2009-4469
|
2017-08-17 10:31 |
2009-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258430
|
- |
|
ektron
|
cms4000.net
|
Multiple cross-site scripting (XSS) vulnerabilities in WorkArea/ContentDesigner/ekformsiframe.aspx in Ektron CMS400.NET 7.6.1.53 and 7.6.6.47, and possibly 7.52 through 7.66sp2, allow remote attacker…
|
CWE-79
Cross-site Scripting
|
CVE-2009-4473
|
2017-08-17 10:31 |
2009-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|