|
303211
|
- |
|
xfce
|
xfce
|
Xfce4-session 4.5.91 in Xfce does not lock the screen when the suspend or hibernate button is pressed, which might make it easier for physically proximate attackers to access an unattended laptop via…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-4996
|
2024-11-21 10:10 |
2010-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303212
|
- |
|
twiki
|
twiki
|
Cross-site request forgery (CSRF) vulnerability in TWiki before 4.3.2 allows remote attackers to hijack the authentication of arbitrary users for requests that update pages, as demonstrated by a URL …
|
CWE-352
Origin Validation Error
|
CVE-2009-4898
|
2024-11-21 10:10 |
2010-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303213
|
- |
|
smartertools
|
smartertrack
|
Cross-site scripting (XSS) vulnerability in frmTickets.aspx in SmarterTools SmarterTrack before 4.0.3504 allows remote attackers to inject arbitrary web script or HTML via the email address field. N…
|
CWE-79
Cross-site Scripting
|
CVE-2009-4995
|
2024-11-21 10:10 |
2010-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303214
|
- |
|
smartertools
|
smartertrack
|
Cross-site scripting (XSS) vulnerability in frmKBSearch.aspx in SmarterTools SmarterTrack before 4.0.3504 allows remote attackers to inject arbitrary web script or HTML via the search parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2009-4994
|
2024-11-21 10:10 |
2010-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303215
|
- |
|
script-shop24
|
lm_starmail_paidmail
|
PHP remote file inclusion vulnerability in home.php in LM Starmail Paidmail 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.
|
CWE-94
Code Injection
|
CVE-2009-4993
|
2024-11-21 10:10 |
2010-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303216
|
- |
|
script-shop24
|
lm_starmail_paidmail
|
SQL injection vulnerability in paidbanner.php in LM Starmail Paidmail 2.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.
|
CWE-89
SQL Injection
|
CVE-2009-4992
|
2024-11-21 10:10 |
2010-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303217
|
- |
|
omnistaretools
|
omnistar_recruiting
|
Cross-site scripting (XSS) vulnerability in users/resume_register.php in Omnistar Recruiting allows remote attackers to inject arbitrary web script or HTML via the job2 parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2009-4991
|
2024-11-21 10:10 |
2010-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303218
|
- |
|
jrbcs
|
webform_report
|
Cross-site scripting (XSS) vulnerability in the Webform report module 5.x and 6.x for Drupal allows remote attackers to inject arbitrary web script or HTML via a submission.
|
CWE-79
Cross-site Scripting
|
CVE-2009-4990
|
2024-11-21 10:10 |
2010-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303219
|
- |
|
ajsquare
|
aj_auction_pro-oopd
|
Cross-site scripting (XSS) vulnerability in index.php in AJ Auction Pro OOPD 3.0 allows remote attackers to inject arbitrary web script or HTML via the txtkeyword parameter in a search action.
|
CWE-79
Cross-site Scripting
|
CVE-2009-4989
|
2024-11-21 10:10 |
2010-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303220
|
- |
|
sap
|
business_one_2005-a
|
Stack-based buffer overflow in NT_Naming_Service.exe in SAP Business One 2005 A 6.80.123 and 6.80.320 allows remote attackers to execute arbitrary code via a long GIOP request to TCP port 30000.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-4988
|
2024-11-21 10:10 |
2010-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|