258591
|
- |
|
deluxebb
|
deluxebb
|
misc.php in DeluxeBB 1.3 allows remote attackers to register accounts without a valid email address via a valemail action with the valmem set to a pre-assigned user ID, which is visible from a member…
|
CWE-20
Improper Input Validation
|
CVE-2009-4467
|
2017-08-17 10:31 |
2009-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258592
|
- |
|
deluxebb
|
deluxebb
|
Cross-site scripting (XSS) vulnerability in misc.php in DeluxeBB 1.3 allows remote attackers to inject arbitrary web script or HTML via the page parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2009-4468
|
2017-08-17 10:31 |
2009-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258593
|
- |
|
giombetti
|
phppowercards
|
Multiple cross-site scripting (XSS) vulnerabilities in pagenumber.inc.php in phpPowerCards 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO, the (2) archiv para…
|
CWE-79
Cross-site Scripting
|
CVE-2009-4469
|
2017-08-17 10:31 |
2009-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258594
|
- |
|
ektron
|
cms4000.net
|
Multiple cross-site scripting (XSS) vulnerabilities in WorkArea/ContentDesigner/ekformsiframe.aspx in Ektron CMS400.NET 7.6.1.53 and 7.6.6.47, and possibly 7.52 through 7.66sp2, allow remote attacker…
|
CWE-79
Cross-site Scripting
|
CVE-2009-4473
|
2017-08-17 10:31 |
2009-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258595
|
- |
|
novell
|
imanager
|
Stack-based buffer overflow in the eDirectory plugin in Novell iManager before 2.7.3 allows remote attackers to execute arbitrary code via vectors that trigger long arguments to an unspecified sub-ap…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-4486
|
2017-08-17 10:31 |
2010-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258596
|
- |
|
indymedia
|
oscailt
|
Directory traversal vulnerability in index.php in Oscailt 3.3, when Use Friendly URL's is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the obj_…
|
CWE-22
Path Traversal
|
CVE-2009-4512
|
2017-08-17 10:31 |
2010-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258597
|
- |
|
john_vandyk
|
workflow
|
Multiple cross-site scripting (XSS) vulnerabilities in the Workflow module 5.x before 5.x-2.4 and 6.x before 6.x-1.2, a module for Drupal, allow remote authenticated users, with "administer workflow"…
|
CWE-79
Cross-site Scripting
|
CVE-2009-4513
|
2017-08-17 10:31 |
2010-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258598
|
- |
|
ortro
|
ortro
|
Multiple unspecified vulnerabilities in Ortro before 1.3.4 have unknown impact and attack vectors.
|
NVD-CWE-noinfo
|
CVE-2009-4519
|
2017-08-17 10:31 |
2010-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258599
|
- |
|
bloofox
|
bloofoxcms
|
Cross-site scripting (XSS) vulnerability in search.5.html in BloofoxCMS 0.3.5 allows remote attackers to inject arbitrary web script or HTML via the search parameter to index.php. NOTE: some of thes…
|
CWE-79
Cross-site Scripting
|
CVE-2009-4522
|
2017-08-17 10:31 |
2010-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258600
|
- |
|
zainu
|
zainu
|
Cross-site scripting (XSS) vulnerability in index.php in Zainu 1.0 allows remote attackers to inject arbitrary web script or HTML via the searchSongKeyword parameter in a SearchSong action.
|
CWE-79
Cross-site Scripting
|
CVE-2009-4523
|
2017-08-17 10:31 |
2010-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|