|
287681
|
- |
|
mcafee
|
intrushield_network_security_manager
|
McAfee IntruShield Network Security Manager (NSM) before 5.1.11.8.1 does not include the HTTPOnly flag in the Set-Cookie header for the session identifier, which allows remote attackers to hijack a s…
|
CWE-79
Cross-site Scripting
|
CVE-2009-3566
|
2018-10-11 04:47 |
2009-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287682
|
- |
|
autodesk
|
autodesk_softimage autodesk_softimage_xsi
|
Autodesk Softimage 7.x and Softimage XSI 6.x allow remote attackers to execute arbitrary JavaScript code via a scene package containing a Scene Table of Contents (aka .scntoc) file with a Script_Cont…
|
CWE-94
Code Injection
|
CVE-2009-3576
|
2018-10-11 04:47 |
2009-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287683
|
- |
|
autodesk
|
3ds_max
|
Autodesk 3D Studio Max (3DSMax) 6 through 9 and 2008 through 2010 allows remote attackers to execute arbitrary code via a .max file with a MAXScript statement that calls the DOSCommand method, relate…
|
CWE-94
Code Injection
|
CVE-2009-3577
|
2018-10-11 04:47 |
2009-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287684
|
- |
|
autodesk
|
alias_wavefront_maya autodesk_maya
|
Autodesk Maya 8.0, 8.5, 2008, 2009, and 2010 and Alias Wavefront Maya 6.5 and 7.0 allow remote attackers to execute arbitrary code via a (1) .ma or (2) .mb file that uses the Maya Embedded Language (…
|
CWE-94
Code Injection
|
CVE-2009-3578
|
2018-10-11 04:47 |
2009-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287685
|
- |
|
mortbay
|
jetty
|
Cross-site scripting (XSS) vulnerability in the CookieDump.java sample application in Mort Bay Jetty 6.1.19 and 6.1.20 allows remote attackers to inject arbitrary web script or HTML via the Value par…
|
CWE-79
Cross-site Scripting
|
CVE-2009-3579
|
2018-10-11 04:47 |
2009-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287686
|
- |
|
sql-ledger
|
sql-ledger
|
Cross-site request forgery (CSRF) vulnerability in am.pl in SQL-Ledger 2.8.24 allows remote attackers to hijack the authentication of arbitrary users for requests that change a password via the login…
|
CWE-352
Origin Validation Error
|
CVE-2009-3580
|
2018-10-11 04:47 |
2009-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287687
|
- |
|
sql-ledger
|
sql-ledger
|
Multiple cross-site scripting (XSS) vulnerabilities in SQL-Ledger 2.8.24 allow remote authenticated users to inject arbitrary web script or HTML via (1) the DCN Description field in the Accounts Rece…
|
CWE-79
Cross-site Scripting
|
CVE-2009-3581
|
2018-10-11 04:47 |
2009-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287688
|
- |
|
sql-ledger
|
sql-ledger
|
Multiple SQL injection vulnerabilities in the delete subroutine in SQL-Ledger 2.8.24 allow remote authenticated users to execute arbitrary SQL commands via the (1) id and possibly (2) db parameters i…
|
CWE-89
SQL Injection
|
CVE-2009-3582
|
2018-10-11 04:47 |
2009-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287689
|
- |
|
sql-ledger
|
sql-ledger
|
Directory traversal vulnerability in the Preferences menu item in SQL-Ledger 2.8.24 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the countrycode field.
|
CWE-22
Path Traversal
|
CVE-2009-3583
|
2018-10-11 04:47 |
2009-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287690
|
- |
|
sql-ledger
|
sql-ledger
|
SQL-Ledger 2.8.24 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an…
|
CWE-16
Configuration
|
CVE-2009-3584
|
2018-10-11 04:47 |
2009-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|