258581
|
- |
|
ikemcg
|
phpinstantgallery
|
Cross-site scripting (XSS) vulnerability in admin.php in phpInstantGallery 1.1 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.
|
CWE-79
Cross-site Scripting
|
CVE-2009-4446
|
2017-08-17 10:31 |
2009-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258582
|
- |
|
jax_scripts
|
jax_guestbook
|
Jax Guestbook 3.5.0 allows remote attackers to bypass authentication and modify administrator settings via a direct request to admin/guestbook.admin.php.
|
CWE-287
Improper Authentication
|
CVE-2009-4447
|
2017-08-17 10:31 |
2009-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258583
|
- |
|
microsoft
|
internet_information_services
|
Microsoft Internet Information Services (IIS), when used in conjunction with unspecified third-party upload applications, allows remote attackers to create empty files with arbitrary extensions via a…
|
CWE-20
Improper Input Validation
|
CVE-2009-4445
|
2017-08-17 10:31 |
2009-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258584
|
- |
|
softcab
|
sound_converter_activex
|
Insecure method vulnerability in SoftCab Sound Converter ActiveX control (sndConverter.ocx) 1.2 allows remote attackers to create or overwrite arbitrary files via the SaveFormat method. NOTE: some o…
|
NVD-CWE-Other
|
CVE-2009-4453
|
2017-08-17 10:31 |
2009-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258585
|
- |
|
softcab
|
sound_converter_activex
|
Per: http://cwe.mitre.org/data/definitions/749.html
'CWE-749: Exposed Dangerous Method or Function'
|
NVD-CWE-Other
|
CVE-2009-4453
|
2017-08-17 10:31 |
2009-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258586
|
- |
|
freepbx
|
freepbx
|
Multiple cross-site scripting (XSS) vulnerabilities in FreePBX 2.5.2 and 2.6.0rc2, and possibly other versions, allow remote attackers to inject arbitrary web script or HTML via the (1) tech paramete…
|
CWE-79
Cross-site Scripting
|
CVE-2009-4458
|
2017-08-17 10:31 |
2009-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258587
|
- |
|
redmine
|
redmine
|
Redmine 0.8.7 and earlier uses the title tag before defining the character encoding in a meta tag, which allows remote attackers to conduct cross-site scripting (XSS) attacks and inject arbitrary scr…
|
CWE-79
Cross-site Scripting
|
CVE-2009-4459
|
2017-08-17 10:31 |
2009-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258588
|
- |
|
activewebsoftwares
|
active_business_directory
|
Cross-site scripting (XSS) vulnerability in searchadvance.asp in Active Business Directory 2 allows remote attackers to inject arbitrary web script or HTML via the search parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2009-4464
|
2017-08-17 10:31 |
2009-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258589
|
- |
|
deluxebb
|
deluxebb
|
DeluxeBB 1.3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain user and configuration information, log data, and gain administr…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-4465
|
2017-08-17 10:31 |
2009-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258590
|
- |
|
deluxebb
|
deluxebb
|
DeluxeBB 1.3 allows remote attackers to obtain sensitive information via a crafted page parameter to misc.php, which reveals the installation path in an error message. NOTE: this issue might be resu…
|
CWE-200
Information Exposure
|
CVE-2009-4466
|
2017-08-17 10:31 |
2009-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|