|
287561
|
- |
|
microsoft windows
|
windows_2000 windows_2003_server windows_xp media_player
|
Stack-based buffer overflow in the Intel Indeo41 codec for Windows Media Player in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code vi…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-4310
|
2018-10-11 04:49 |
2009-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287562
|
- |
|
zen-cart
|
zen_cart
|
extras/curltest.php in Zen Cart 1.3.8 and 1.3.8a, and possibly other versions, allows remote attackers to read arbitrary files via a file:// URI. NOTE: some of these details are obtained from third …
|
CWE-20
Improper Input Validation
|
CVE-2009-4321
|
2018-10-11 04:49 |
2009-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287563
|
- |
|
zen-cart
|
zen_cart
|
extras/ipn_test_return.php in Zen Cart allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message.
|
CWE-200
Information Exposure
|
CVE-2009-4322
|
2018-10-11 04:49 |
2009-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287564
|
- |
|
liran_tal
|
daloradius
|
Cross-site scripting (XSS) vulnerability in daloradius-users/login.php in daloRADIUS 0.9-8 and earlier allows remote attackers to inject arbitrary web script or HTML via the error parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2009-4347
|
2018-10-11 04:49 |
2009-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287565
|
- |
|
wscreator
|
wscreator
|
SQL injection vulnerability in ADMIN/loginaction.php in WSCreator 1.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the Email (aka username) parame…
|
CWE-89
SQL Injection
|
CVE-2009-4351
|
2018-10-11 04:49 |
2009-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287566
|
- |
|
nullsoft
|
winamp
|
Multiple integer overflows in the jpeg.w5s and png.w5s filters in Winamp before 5.57 allow remote attackers to execute arbitrary code via malformed (1) JPEG or (2) PNG data in an MP3 file.
|
CWE-189
Numeric Errors
|
CVE-2009-4356
|
2018-10-11 04:49 |
2009-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287567
|
- |
|
sitecore
|
staging_module
|
The Staging Webservice ("sitecore modules/staging/service/api.asmx") in Sitecore Staging Module 5.4.0 rev.080625 and earlier allows remote attackers to bypass authentication and (1) upload files, (2)…
|
CWE-287
Improper Authentication
|
CVE-2009-4367
|
2018-10-11 04:49 |
2009-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287568
|
- |
|
bookingcentre
|
booking_system_for_hotels_group
|
SQL injection vulnerability in hotel_tiempolibre_ext.php in Venalsur Booking Centre Booking System for Hotels Group, when magic_quotes_gpc is enabled, allows remote attackers to execute arbitrary SQL…
|
CWE-89
SQL Injection
|
CVE-2009-4386
|
2018-10-11 04:49 |
2009-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287569
|
- |
|
sql-ledger
|
sql-ledger
|
The default configuration of SQL-Ledger 2.8.24 allows remote attackers to perform unspecified administrative operations by providing an arbitrary password to the admin interface.
|
CWE-16
Configuration
|
CVE-2009-4402
|
2018-10-11 04:49 |
2009-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287570
|
- |
|
rumbacms
|
rumba_xml
|
Cross-site scripting (XSS) vulnerability in index.php in Rumba XML 1.8 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO. NOTE: some of these details are obtained from…
|
CWE-79
Cross-site Scripting
|
CVE-2009-4403
|
2018-10-11 04:49 |
2009-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|