|
287661
|
- |
|
snitz_communications
|
snitz_forums_2000
|
Multiple cross-site scripting (XSS) vulnerabilities in Snitz Forums 2000 3.4.07 allow remote attackers to inject arbitrary web script or HTML via (1) the url parameter to pop_send_to_friend.asp, rela…
|
CWE-79
Cross-site Scripting
|
CVE-2009-4554
|
2018-10-11 04:49 |
2010-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287662
|
- |
|
quickheal
|
antivirus_plus_2009 total_security_2009
|
Quick Heal AntiVirus Plus 2009 10.00 SP1 and Quick Heal Total Security 2009 10.00 SP1 use weak permissions (Everyone: Full Control) for the product files, which allows local users to gain privileges …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-4556
|
2018-10-11 04:49 |
2010-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287663
|
- |
|
phpshop
|
phpshop
|
Cross-site scripting (XSS) vulnerability in PhpShop 0.8.1 allows remote attackers to inject arbitrary web script or HTML via the order_id parameter in an order/order_print action to the default URI.
|
CWE-79
Cross-site Scripting
|
CVE-2009-4570
|
2018-10-11 04:49 |
2010-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287664
|
- |
|
phpshop
|
phpshop
|
Cross-site request forgery (CSRF) vulnerability in PhpShop 0.8.1 allows remote attackers to hijack the authentication of arbitrary users for requests that invoke the cartAdd function in a shop/cart a…
|
CWE-352
Origin Validation Error
|
CVE-2009-4572
|
2018-10-11 04:49 |
2010-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287665
|
- |
|
phpshop
|
phpshop
|
Multiple SQL injection vulnerabilities in index.php in PhpShop 0.8.1 allow remote attackers to execute arbitrary SQL commands via the (1) module_id parameter in an admin/function_list action, the (2)…
|
CWE-89
SQL Injection
|
CVE-2009-4571
|
2018-10-11 04:49 |
2010-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287666
|
- |
|
cherokee
|
cherokee
|
Cherokee Web Server 0.5.4 allows remote attackers to cause a denial of service (daemon crash) via an MS-DOS reserved word in a URI, as demonstrated by the AUX reserved word.
|
NVD-CWE-Other
|
CVE-2009-4587
|
2018-10-11 04:49 |
2010-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287667
|
- |
|
south_river_technologies
|
webdrive
|
South River Technologies WebDrive 9.02 build 2232 installs the WebDrive Service without a security descriptor, which allows local users to (1) stop the service via the stop command, (2) execute arbit…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-4606
|
2018-10-11 04:49 |
2010-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287668
|
- |
|
overlandstorage
|
snap_server_410 guardianos
|
The command line interface in Overland Storage Snap Server 410 with GuardianOS 5.1.041 runs the "less" utility with a higher-privileged uid than the CLI user and without sufficient restriction on she…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-4607
|
2018-10-11 04:49 |
2010-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287669
|
- |
|
novell
|
edirectory
|
Stack-based buffer overflow in the dhost module in Novell eDirectory 8.8 SP5 for Windows allows remote authenticated users to cause a denial of service (dhost.exe crash) and possibly execute arbitrar…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-4653
|
2018-10-11 04:49 |
2010-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287670
|
- |
|
novell
|
edirectory
|
Stack-based buffer overflow in the dhost module in Novell eDirectory 8.8 SP5 for Windows allows remote authenticated users to execute arbitrary code via long sadminpwd and verifypwd parameters in a s…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-4654
|
2018-10-11 04:49 |
2010-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|