|
287821
|
- |
|
joomlahbs
|
com_hbssearch
|
Multiple SQL injection vulnerabilities in the Hotel Booking Reservation System (aka HBS or com_hbssearch) component for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) h_…
|
CWE-89
SQL Injection
|
CVE-2009-3357
|
2018-10-11 04:43 |
2009-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287822
|
- |
|
joomlahbs
|
com_hbssearch
|
Cross-site scripting (XSS) vulnerability in the Hotel Booking Reservation System (aka HBS or com_hbssearch) component for Joomla! allows remote attackers to inject arbitrary web script or HTML via th…
|
CWE-79
Cross-site Scripting
|
CVE-2009-3368
|
2018-10-11 04:43 |
2009-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287823
|
- |
|
mozilla
|
bugzilla
|
Bugzilla 3.3.1 through 3.4.4, 3.5.1, and 3.5.2 does not allow group restrictions to be preserved throughout the process of moving a bug to a different product category, which allows remote attackers …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-3387
|
2018-10-11 04:43 |
2010-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287824
|
- |
|
kayako
|
supportsuite
|
Cross-site scripting (XSS) vulnerability in Kayako SupportSuite 3.50.06 allows remote attackers to inject arbitrary web script or HTML via the subject field in a ticket.
|
CWE-79
Cross-site Scripting
|
CVE-2009-3427
|
2018-10-11 04:43 |
2009-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287825
|
- |
|
alienvault
|
ossim
|
Multiple SQL injection vulnerabilities in Open Source Security Information Management (OSSIM) before 2.1.2 allow remote authenticated users to execute arbitrary SQL commands via the id_document param…
|
CWE-89
SQL Injection
|
CVE-2009-3439
|
2018-10-11 04:43 |
2009-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287826
|
- |
|
alienvault
|
ossim
|
Cross-site scripting (XSS) vulnerability in Open Source Security Information Management (OSSIM) before 2.1.2 allows remote attackers to inject arbitrary web script or HTML via the option parameter to…
|
CWE-79
Cross-site Scripting
|
CVE-2009-3440
|
2018-10-11 04:43 |
2009-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287827
|
- |
|
alienvault
|
ossim
|
Open Source Security Information Management (OSSIM) before 2.1.2 allows remote attackers to bypass authentication, and read graphs or infrastructure information, via a direct request to (1) graphs/al…
|
CWE-287
Improper Authentication
|
CVE-2009-3441
|
2018-10-11 04:43 |
2009-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287828
|
- |
|
e107
|
e107
|
Cross-site scripting (XSS) vulnerability in email.php in e107 0.7.16 and earlier allows remote attackers to inject arbitrary web script or HTML via the HTTP Referer header in a news.1 (aka news to em…
|
CWE-79
Cross-site Scripting
|
CVE-2009-3444
|
2018-10-11 04:43 |
2009-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287829
|
- |
|
radactive
|
i-load
|
Unrestricted file upload vulnerability in RADactive I-Load before 2008.2.5.0 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, and then sending a req…
|
CWE-362
Race Condition
|
CVE-2009-3447
|
2018-10-11 04:43 |
2009-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287830
|
- |
|
radactive
|
i-load
|
Multiple cross-site scripting (XSS) vulnerabilities in WebCoreModule.ashx in RADactive I-Load before 2008.2.5.0 allow remote attackers to inject arbitrary web script or HTML via parameters with names…
|
CWE-79
Cross-site Scripting
|
CVE-2009-3450
|
2018-10-11 04:43 |
2009-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|