260621
|
- |
|
opensc-project
|
opensc
|
OpenSC before 0.11.7 allows physically proximate attackers to bypass intended PIN requirements and read private data objects via a (1) low level APDU command or (2) debugging tool, as demonstrated by…
|
CWE-310
Cryptographic Issues
|
CVE-2009-0368
|
2017-08-8 10:33 |
2009-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260622
|
- |
|
ephpscripts
|
e-php_cms
|
SQL injection vulnerability in browsecats.php in E-Php CMS allows remote attackers to execute arbitrary SQL commands via the cid parameter.
|
CWE-89
SQL Injection
|
CVE-2009-0401
|
2017-08-8 10:33 |
2009-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260623
|
- |
|
bioinformatics
|
htmlawed
|
Multiple cross-site scripting (XSS) vulnerabilities in Bioinformatics htmLawed 1.1.3 and 1.1.4 allow remote attackers to inject arbitrary web script or HTML via invalid Cascading Style Sheets (CSS) e…
|
CWE-79
Cross-site Scripting
|
CVE-2009-0404
|
2017-08-8 10:33 |
2009-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260624
|
- |
|
oscommerce
|
oscommerce
|
Cross-site request forgery (CSRF) vulnerability in osCommerce 2.2 RC 2a allows remote attackers to hijack the authentication of administrators.
|
CWE-352
Origin Validation Error
|
CVE-2009-0408
|
2017-08-8 10:33 |
2009-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260625
|
- |
|
google
|
chrome
|
Google Chrome before 1.0.154.46 does not properly restrict access from web pages to the (1) Set-Cookie and (2) Set-Cookie2 HTTP response headers, which allows remote attackers to obtain sensitive inf…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-0411
|
2017-08-8 10:33 |
2009-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260626
|
- |
|
roundcube
|
webmail
|
Cross-site scripting (XSS) vulnerability in RoundCube Webmail (roundcubemail) 0.2 stable allows remote attackers to inject arbitrary web script or HTML via the background attribute embedded in an HTM…
|
CWE-79
Cross-site Scripting
|
CVE-2009-0413
|
2017-08-8 10:33 |
2009-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260627
|
- |
|
microsoft
|
xml_core_services
|
Microsoft XML Core Services, as used in Microsoft Expression Web, Office, Internet Explorer 6 and 7, and other products, does not properly restrict access from web pages to Set-Cookie2 HTTP response …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-0419
|
2017-08-8 10:33 |
2009-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260628
|
- |
|
an_guestbook
|
an_guestbook
|
Cross-site scripting (XSS) vulnerability in sign1.php in AN Guestbook (ANG) before 0.7.7 allows remote attackers to inject arbitrary web script or HTML via the country parameter, which is not properl…
|
CWE-79
Cross-site Scripting
|
CVE-2009-0424
|
2017-08-8 10:33 |
2009-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260629
|
- |
|
ibm
|
websphere_application_server
|
The installation process for the File Transfer servlet in the System Management/Repository component in IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.19 does not enable the secure version…
|
CWE-16
Configuration
|
CVE-2009-0432
|
2017-08-8 10:33 |
2009-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260630
|
- |
|
ibm
|
websphere_application_server
|
Unspecified vulnerability in IBM WebSphere Application Server (WAS) 5.1.x before 5.1.1.19, 6.0.x before 6.0.2.29, and 6.1.x before 6.1.0.19, when Web Server plug-in content buffering is enabled, allo…
|
NVD-CWE-noinfo
|
CVE-2009-0433
|
2017-08-8 10:33 |
2009-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|