|
287651
|
- |
|
cherokee-project
|
cherokee
|
header.c in Cherokee before 0.99.32 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary…
|
CWE-20
Improper Input Validation
|
CVE-2009-4489
|
2018-10-11 04:49 |
2010-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287652
|
- |
|
acme
|
mini_httpd
|
mini_httpd 1.19 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwri…
|
CWE-20
Improper Input Validation
|
CVE-2009-4490
|
2018-10-11 04:49 |
2010-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287653
|
- |
|
orion
|
orion_application_server
|
Orion Application Server 2.0.7 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary comm…
|
CWE-20
Improper Input Validation
|
CVE-2009-4493
|
2018-10-11 04:49 |
2010-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287654
|
- |
|
aol
|
aolserver
|
AOLserver 4.5.1 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwri…
|
CWE-20
Improper Input Validation
|
CVE-2009-4494
|
2018-10-11 04:49 |
2010-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287655
|
- |
|
yaws
|
yaws
|
Yaws 1.85 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite fil…
|
CWE-20
Improper Input Validation
|
CVE-2009-4495
|
2018-10-11 04:49 |
2010-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287656
|
- |
|
boa
|
boa
|
Boa 0.94.14rc21 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwri…
|
CWE-20
Improper Input Validation
|
CVE-2009-4496
|
2018-10-11 04:49 |
2010-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287657
|
- |
|
alkacon
|
oamp_comments
|
Multiple cross-site scripting (XSS) vulnerabilities in OpenCMS OAMP Comments Module 1.0.1 allow remote attackers to inject arbitrary web script or HTML via the name field in a comment, and other unsp…
|
CWE-79
Cross-site Scripting
|
CVE-2009-4505
|
2018-10-11 04:49 |
2010-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287658
|
- |
|
vsecurity
|
tandberg_video_communication_server
|
Multiple directory traversal vulnerabilities in the web administration interface on the TANDBERG Video Communication Server (VCS) before X5.1 allow remote authenticated users to read arbitrary files …
|
CWE-200
Information Exposure
|
CVE-2009-4511
|
2018-10-11 04:49 |
2010-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287659
|
- |
|
eclipse
|
birt
|
Cross-site scripting (XSS) vulnerability in birt-viewer/run in Eclipse Business Intelligence and Reporting Tools (BIRT) before 2.5.0, as used in KonaKart and other products, allows remote attackers t…
|
CWE-79
Cross-site Scripting
|
CVE-2009-4521
|
2018-10-11 04:49 |
2010-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287660
|
- |
|
sqlitemanager
|
sqlitemanager
|
Cross-site scripting (XSS) vulnerability in main.php in SQLiteManager 1.2.0 allows remote attackers to inject arbitrary web script or HTML via the redirect parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2009-4539
|
2018-10-11 04:49 |
2010-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|