|
287581
|
- |
|
intellicom
|
netbiter_webscada_firmware netbiter_webscada_ws100 netbiter_webscada_ws200
|
Intellicom NetBiter WebSCADA devices use default passwords for the HICP network configuration service, which makes it easier for remote attackers to modify network settings and cause a denial of serv…
|
CWE-255
Credentials Management
|
CVE-2009-4463
|
2018-10-11 04:49 |
2009-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287582
|
- |
|
dvbbs
|
dvbbs
|
SQL injection vulnerability in boardrule.php in DVBBS 2.0 allows remote attackers to execute arbitrary SQL commands via the groupboardid parameter.
|
CWE-89
SQL Injection
|
CVE-2009-4470
|
2018-10-11 04:49 |
2009-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287583
|
- |
|
cherokee-project
|
cherokee
|
header.c in Cherokee before 0.99.32 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary…
|
CWE-20
Improper Input Validation
|
CVE-2009-4489
|
2018-10-11 04:49 |
2010-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287584
|
- |
|
acme
|
mini_httpd
|
mini_httpd 1.19 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwri…
|
CWE-20
Improper Input Validation
|
CVE-2009-4490
|
2018-10-11 04:49 |
2010-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287585
|
- |
|
orion
|
orion_application_server
|
Orion Application Server 2.0.7 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary comm…
|
CWE-20
Improper Input Validation
|
CVE-2009-4493
|
2018-10-11 04:49 |
2010-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287586
|
- |
|
aol
|
aolserver
|
AOLserver 4.5.1 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwri…
|
CWE-20
Improper Input Validation
|
CVE-2009-4494
|
2018-10-11 04:49 |
2010-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287587
|
- |
|
yaws
|
yaws
|
Yaws 1.85 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite fil…
|
CWE-20
Improper Input Validation
|
CVE-2009-4495
|
2018-10-11 04:49 |
2010-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287588
|
- |
|
boa
|
boa
|
Boa 0.94.14rc21 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwri…
|
CWE-20
Improper Input Validation
|
CVE-2009-4496
|
2018-10-11 04:49 |
2010-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287589
|
- |
|
alkacon
|
oamp_comments
|
Multiple cross-site scripting (XSS) vulnerabilities in OpenCMS OAMP Comments Module 1.0.1 allow remote attackers to inject arbitrary web script or HTML via the name field in a comment, and other unsp…
|
CWE-79
Cross-site Scripting
|
CVE-2009-4505
|
2018-10-11 04:49 |
2010-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287590
|
- |
|
vsecurity
|
tandberg_video_communication_server
|
Multiple directory traversal vulnerabilities in the web administration interface on the TANDBERG Video Communication Server (VCS) before X5.1 allow remote authenticated users to read arbitrary files …
|
CWE-200
Information Exposure
|
CVE-2009-4511
|
2018-10-11 04:49 |
2010-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|