258711
|
- |
|
ecardmax.com
|
formxp
|
Cross-site scripting (XSS) vulnerability in survey_result.php in eCardMAX FormXP 2007 allows remote attackers to inject arbitrary web script or HTML via the sid parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2009-3598
|
2017-08-17 10:31 |
2009-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258712
|
- |
|
freewebscriptz
|
hubscript
|
Cross-site scripting (XSS) vulnerability in single_winner1.php in HUBScript 1.0 allows remote attackers to inject arbitrary web script or HTML via the bid_id parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2009-3599
|
2017-08-17 10:31 |
2009-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258713
|
- |
|
freewebscriptz
|
hubscript
|
HUBScript 1.0 allows remote attackers to obtain configuration information via a direct request to manage/phpinfo.php, which calls the phpinfo function.
|
CWE-200
Information Exposure
|
CVE-2009-3600
|
2017-08-17 10:31 |
2009-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258714
|
- |
|
scriptsez
|
ultimate_poll
|
Cross-site scripting (XSS) vulnerability in demo_page.php in Scriptsez Ultimate Poll allows remote attackers to inject arbitrary web script or HTML via the clr parameter in a vote action.
|
CWE-79
Cross-site Scripting
|
CVE-2009-3601
|
2017-08-17 10:31 |
2009-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258715
|
- |
|
nlnetlabs
|
unbound
|
Unbound before 1.3.4 does not properly verify signatures for NSEC3 records, which allows remote attackers to cause secure delegations to be downgraded via DNS spoofing or other DNS-related attacks in…
|
CWE-310
Cryptographic Issues
|
CVE-2009-3602
|
2017-08-17 10:31 |
2009-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258716
|
- |
|
perl
|
perl
|
Perl 5.10.1 allows context-dependent attackers to cause a denial of service (application crash) via a UTF-8 character with a large, invalid codepoint, which is not properly handled during a regular-e…
|
NVD-CWE-Other
|
CVE-2009-3626
|
2017-08-17 10:31 |
2009-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258717
|
- |
|
derrick_oswald
|
html-parser
|
The decode_entities function in util.c in HTML-Parser before 3.63 allows context-dependent attackers to cause a denial of service (infinite loop) via an incomplete SGML numeric character reference, w…
|
CWE-20
Improper Input Validation
|
CVE-2009-3627
|
2017-08-17 10:31 |
2009-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258718
|
- |
|
typo3
|
typo3
|
The Backend subcomponent in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2 allows remote authenticated users to determine an encryption key via crafted …
|
CWE-200
Information Exposure
|
CVE-2009-3628
|
2017-08-17 10:31 |
2009-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258719
|
- |
|
typo3
|
typo3
|
Multiple cross-site scripting (XSS) vulnerabilities in the Backend subcomponent in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2 allow remote authentic…
|
CWE-79
Cross-site Scripting
|
CVE-2009-3629
|
2017-08-17 10:31 |
2009-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258720
|
- |
|
typo3
|
typo3
|
The Backend subcomponent in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2 allows remote authenticated users to place arbitrary web sites in TYPO3 backe…
|
NVD-CWE-Other
|
CVE-2009-3630
|
2017-08-17 10:31 |
2009-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|