|
287641
|
- |
|
cacti
|
cacti
|
Cacti 0.8.7e and earlier allows remote authenticated administrators to gain privileges by modifying the "Data Input Method" for the "Linux - Get Memory Usage" setting to contain arbitrary commands.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-4112
|
2018-10-11 04:48 |
2009-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287642
|
- |
|
cutephp korn19
|
cutenews utf-8_cutenews
|
Static code injection vulnerability in the Categories module in CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b allows remote authenticated users with application administrative privileges to inj…
|
CWE-94
Code Injection
|
CVE-2009-4113
|
2018-10-11 04:48 |
2009-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287643
|
- |
|
kaspersky
|
kaspersky_anti-virus
|
kl1.sys in Kaspersky Anti-Virus 2010 9.0.0.463, and possibly other versions before 9.0.0.736, does not properly validate input to IOCTL 0x0022c008, which allows local users to cause a denial of servi…
|
CWE-20
Improper Input Validation
|
CVE-2009-4114
|
2018-10-11 04:48 |
2009-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287644
|
- |
|
cutephp
|
cutenews
|
Multiple static code injection vulnerabilities in the Categories module in CutePHP CuteNews 1.4.6 allow remote authenticated users with application administrative privileges to inject arbitrary PHP c…
|
CWE-94
Code Injection
|
CVE-2009-4115
|
2018-10-11 04:48 |
2009-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287645
|
- |
|
cutephp
|
cutenews
|
Multiple directory traversal vulnerabilities in CutePHP CuteNews 1.4.6, when magic_quotes_gpc is disabled, allow remote authenticated users with editor or administrative application access to read ar…
|
CWE-22
Path Traversal
|
CVE-2009-4116
|
2018-10-11 04:48 |
2009-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287646
|
- |
|
postgresql
|
postgresql
|
PostgreSQL 7.4.x before 7.4.27, 8.0.x before 8.0.23, 8.1.x before 8.1.19, 8.2.x before 8.2.15, 8.3.x before 8.3.9, and 8.4.x before 8.4.2 does not properly manage session-local state during execution…
|
NVD-CWE-Other
|
CVE-2009-4136
|
2018-10-11 04:48 |
2009-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287647
|
- |
|
daz3d
|
daz_studio
|
DAZ Studio 2.3.3.161, 2.3.3.163, and 3.0.1.135 allows remote attackers to execute arbitrary JavaScript code via a (1) .ds, (2) .dsa, (3) .dse, or (4) .dsb file, as demonstrated by code that loads the…
|
CWE-94
Code Injection
|
CVE-2009-4148
|
2018-10-11 04:48 |
2009-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287648
|
- |
|
eshopbuilder
|
eshopbuilde_cms
|
Multiple SQL injection vulnerabilities in Eshopbuilde CMS allow remote attackers to execute arbitrary SQL commands via the sitebid parameter to (1) home-f.asp and (2) opinions-f.asp; (3) sitebid, (4)…
|
CWE-89
SQL Injection
|
CVE-2009-4155
|
2018-10-11 04:48 |
2009-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287649
|
- |
|
roytanck
|
wp-cumulus
|
Cross-site scripting (XSS) vulnerability in Roy Tanck tagcloud.swf, as used in the WP-Cumulus plugin before 1.23 for WordPress and the Joomulus module 2.0 and earlier for Joomla!, allows remote attac…
|
CWE-79
Cross-site Scripting
|
CVE-2009-4168
|
2018-10-11 04:48 |
2009-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287650
|
- |
|
roytanck
|
wp-cumulus
|
WP-Cumulus Plug-in 1.20 for WordPress, and possibly other versions, allows remote attackers to obtain sensitive information via a crafted request to wp-cumulus.php, probably without parameters, which…
|
CWE-200
Information Exposure
|
CVE-2009-4170
|
2018-10-11 04:48 |
2009-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|