Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2009-3203 | 1 Ajsquare | 1 Aj Auction Pro-oopd | 2017-08-16 | 7.5 HIGH | N/A |
SQL injection vulnerability in store.php in AJ Auction Pro OOPD 2.x allows remote attackers to execute arbitrary SQL commands via the id parameter. | |||||
CVE-2009-3204 | 1 Stivaforum | 1 Stiva Forum | 2017-08-16 | 4.3 MEDIUM | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in Stiva Forum 1.0 allow remote attackers to inject arbitrary web script or HTML via the id parameter to (1) demo.php and (2) forum.php, and the PATH_INFO to (3) include_forum.php. | |||||
CVE-2009-3205 | 1 Cbauthority | 1 Cbauthority | 2017-08-16 | 7.5 HIGH | N/A |
SQL injection vulnerability in main.php in CBAuthority allows remote attackers to execute arbitrary SQL commands via the id parameter in a view_product action. | |||||
CVE-2009-3206 | 2 Drewish, Drupal | 2 Imagecache, Drupal | 2017-08-16 | 3.5 LOW | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in the ImageCache module 5.x before 5.x-2.5 and 6.x before 6.x-2.0-beta10, a module for Drupal, allow remote authenticated users, with "administer imagecache" permissions, to inject arbitrary web script or HTML via unspecified vectors. | |||||
CVE-2009-3207 | 2 Drewish, Drupal | 2 Imagecache, Drupal | 2017-08-16 | 6.8 MEDIUM | N/A |
The ImageCache module 5.x before 5.x-2.5 and 6.x before 6.x-2.0-beta10, a module for Drupal, when the private file system is used, does not properly perform access control for derivative images, which allows remote attackers to view arbitrary images via a request that specifies an image's filename. | |||||
CVE-2009-3208 | 1 Prakashatma Mishra | 1 Phpfreebb | 2017-08-16 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in phpfreeBB 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to permalink.php and (2) year parameter to index.php. | |||||
CVE-2009-3209 | 1 Raizlabs | 1 Php Email Manager | 2017-08-16 | 7.5 HIGH | N/A |
SQL injection vulnerability in remove.php in PHP eMail Manager 3.3.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter. | |||||
CVE-2009-3210 | 2 Drupal, Joao Ventura | 2 Drupal, Print | 2017-08-16 | 3.5 LOW | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in the Print (aka Printer, e-mail and PDF versions) module 5.x before 5.x-4.8 and 6.x before 6.x-1.8, a module for Drupal, allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | |||||
CVE-2009-3211 | 1 Dimofinf | 1 Infinity Script | 2017-08-16 | 6.8 MEDIUM | N/A |
Directory traversal vulnerability in VivaPrograms Infinity Script 2.x.x, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the options[style_dir] parameter to the default URI. | |||||
CVE-2009-3212 | 1 Dimofinf | 1 Infinity Script | 2017-08-16 | 6.8 MEDIUM | N/A |
SQL injection vulnerability in VivaPrograms Infinity Script 2.x.x, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the username field. | |||||
CVE-2009-3213 | 1 Broid | 1 Broid | 2017-08-16 | 9.3 HIGH | N/A |
Stack-based buffer overflow in broid 1.0 Beta 3a allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long string in a .mp3 file. | |||||
CVE-2009-3221 | 1 Basicunivers.free.fr | 1 Audio Lib Player | 2017-08-16 | 9.3 HIGH | N/A |
Stack-based buffer overflow in Audio Lib Player (ALP) allows remote attackers to execute arbitrary code via a long URL in a .m3u playlist file. | |||||
CVE-2009-3222 | 1 Freewebscriptz | 1 Honest Traffic | 2017-08-16 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in index.php in FreeWebScriptz Honest Traffic (FWSHT) 1.x allows remote attackers to inject arbitrary web script or HTML via the msg parameter. | |||||
CVE-2009-3255 | 1 Thomas Cuchta | 1 Rash | 2017-08-16 | 6.8 MEDIUM | N/A |
SQL injection vulnerability in RASH Quote Management System (RQMS) 1.2.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the user parameter in an admin action to the default URI. | |||||
CVE-2009-3259 | 1 Thomas Cuchta | 1 Rash | 2017-08-16 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in RASH Quote Management System (RQMS) 1.2.2 allow remote attackers to execute arbitrary SQL commands via (1) the search parameter in a search action, (2) the quote parameter in a quote addition, or (3) a User_Name cookie in unspecified administrative actions. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |||||
CVE-2009-3300 | 1 Internet2 | 2 Identity Provider, Service Provider | 2017-08-16 | 2.6 LOW | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in the Identity Provider (IdP) 1.3.x before 1.3.4 and 2.x before 2.1.5, and the Service Provider 1.3.x before 1.3.5 and 2.x before 2.3, in Internet2 Middleware Initiative Shibboleth allow remote attackers to inject arbitrary web script or HTML via URLs that are encountered in redirections, and appear in automatically generated forms. | |||||
CVE-2009-3311 | 1 Rssmediascript | 1 Rssmediascript | 2017-08-16 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in index.php in RSSMediaScript allows remote attackers to inject arbitrary web script or HTML via the page parameter. | |||||
CVE-2009-3320 | 1 Zenas | 1 Paolink | 2017-08-16 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in scrivi.php in Zenas PaoLink (aka Pao-Link) 1.0 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO. | |||||
CVE-2009-3355 | 1 Datetopia | 1 Buy Dating Site | 2017-08-16 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in profile.php in Datetopia Buy Dating Site 1.0 allows remote attackers to inject arbitrary web script or HTML via the s_r parameter. | |||||
CVE-2009-3359 | 1 Datetopia | 1 Match Agency Biz | 2017-08-16 | 4.3 MEDIUM | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in Match Agency BiZ 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) important parameter to edit_profile.php and (2) pid parameter to report.php. |