258431
|
- |
|
xerver
|
xerver
|
Xerver HTTP Server 4.32 allows remote attackers to obtain the source code for a web page via an HTTP request with the addition of ::$DATA after the HTML file name.
|
CWE-200
Information Exposure
|
CVE-2009-3544
|
2017-09-19 10:29 |
2009-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258432
|
- |
|
datawizard
|
ftpxq_server
|
DataWizard Technologies FtpXQ FTP Server 3.0 allows remote authenticated users to cause a denial of service (crash) via a long ABOR command.
|
CWE-20
Improper Input Validation
|
CVE-2009-3545
|
2017-09-19 10:29 |
2009-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258433
|
- |
|
wireshark
|
wireshark
|
packet-paltalk.c in the Paltalk dissector in Wireshark 1.2.0 through 1.2.2, on SPARC and certain other platforms, allows remote attackers to cause a denial of service (application crash) via a file t…
|
CWE-20
Improper Input Validation
|
CVE-2009-3549
|
2017-09-19 10:29 |
2009-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258434
|
- |
|
xerver
|
xerver
|
Directory traversal vulnerability in Xerver HTTP Server 4.32 allows remote attackers to read arbitrary files via a full pathname with a drive letter in the currentPath parameter in a chooseDirectory …
|
CWE-22
Path Traversal
|
CVE-2009-3561
|
2017-09-19 10:29 |
2009-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258435
|
- |
|
xerver
|
xerver
|
Cross-site scripting (XSS) vulnerability in Xerver HTTP Server 4.32 allows remote attackers to inject arbitrary web script or HTML via the currentPath parameter in a chooseDirectory action.
|
CWE-79
Cross-site Scripting
|
CVE-2009-3562
|
2017-09-19 10:29 |
2009-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258436
|
- |
|
tony_million
|
tuniac
|
Tuniac 090517c allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long File1 argument in a .pls playlist file, possibly a buffer overflow.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-3574
|
2017-09-19 10:29 |
2009-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258437
|
- |
|
vspanel
|
vs_panel
|
SQL injection vulnerability in showcat.php in VS PANEL 7.3.6 allows remote attackers to execute arbitrary SQL commands via the Cat_ID parameter.
|
CWE-89
SQL Injection
|
CVE-2009-3590
|
2017-09-19 10:29 |
2009-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258438
|
- |
|
vspanel
|
vs_panel
|
SQL injection vulnerability in results.php in VS PANEL 7.5.5 allows remote attackers to execute arbitrary SQL commands via the Cat_ID parameter, a different vector than CVE-2009-3590.
|
CWE-89
SQL Injection
|
CVE-2009-3595
|
2017-09-19 10:29 |
2009-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258439
|
- |
|
joxtechnology
|
ajox_poll
|
JoxTechnology Ajox Poll does not properly restrict access to admin/managepoll.php, which allows remote attackers to bypass authentication and gain administrative access via a direct request.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-3596
|
2017-09-19 10:29 |
2009-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258440
|
- |
|
adium pidgin
|
adium pidgin
|
The OSCAR protocol plugin in libpurple in Pidgin before 2.6.3 and Adium before 1.3.7 allows remote attackers to cause a denial of service (application crash) via crafted contact-list data for (1) ICQ…
|
CWE-399
Resource Management Errors
|
CVE-2009-3615
|
2017-09-19 10:29 |
2009-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|