Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 386 296

Количество 386 296

nvd логотип

CVE-2009-2368

около 17 лет назад

Unspecified vulnerability in Socks Server 5 before 3.7.8-8 has unknown impact and attack vectors.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2009-2367

около 17 лет назад

cgi-bin/makecgi-pro in Iomega StorCenter Pro generates predictable session IDs, which allows remote attackers to hijack active sessions and gain privileges via brute force guessing attacks on the session_id parameter.

CVSS3: 9.8
EPSS: Средний
nvd логотип

CVE-2009-2366

около 17 лет назад

SQL injection vulnerability in login.asp in DataCheck Solutions ForumPal FE 1.1 and ForumPal 1.5 allows remote attackers to execute arbitrary SQL commands via the (1) password parameter in 1.1 and (2) p_password parameter in 1.5. NOTE: some of these details are obtained from third party information.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2009-2365

около 17 лет назад

SQL injection vulnerability in login.asp in DataCheck Solutions GalleryPal FE 1.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2009-2364

около 17 лет назад

Stack-based buffer overflow in Mp3-Nator 2.0 allows remote attackers to execute arbitrary code via (1) a long string in a .plf file and (2) a long string in the listdata.dat file, possibly related to a track entry.

CVSS2: 9.3
EPSS: Средний
nvd логотип

CVE-2009-2363

около 17 лет назад

Stack-based buffer overflow in KUDRSOFT AudioPLUS 2.00.215 allows remote attackers to execute arbitrary code via a .pls playlist file with a playlist entry containing a long File1 argument.

CVSS2: 9.3
EPSS: Низкий
nvd логотип

CVE-2009-2362

около 17 лет назад

Stack-based buffer overflow in KUDRSOFT AudioPLUS 2.0.0.215 allows remote attackers to execute arbitrary code via a long string in a (1) .lst or (2) .m3u playlist file.

CVSS2: 9.3
EPSS: Низкий
nvd логотип

CVE-2009-2361

около 17 лет назад

SQL injection vulnerability in include/class.staff.php in osTicket before 1.6 RC5 allows remote attackers to execute arbitrary SQL commands via the staff username parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2009-2360

около 17 лет назад

Cross-site scripting (XSS) vulnerability in passwd/main.php in the Passwd module before 3.1.1 for Horde allows remote attackers to inject arbitrary web script or HTML via the backend parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2009-2359

около 17 лет назад

Multiple SQL injection vulnerabilities in TekRADIUS 3.0 allow context-dependent attackers to execute arbitrary SQL commands via (1) the GUI client, as demonstrated by input to the Browse Users text box in the Users tab; or (2) the command-line client, as demonstrated by a certain trcli -r command.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2009-2358

около 17 лет назад

TekRADIUS 3.0 uses BUILTIN\Users:R permissions for the TekRADIUS.ini file, which allows local users to obtain obfuscated database credentials by reading this file.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2009-2357

около 17 лет назад

The default configuration of TekRADIUS 3.0 uses the sa account to communicate with Microsoft SQL Server, which makes it easier for remote attackers to obtain privileged access to the database and the underlying Windows operating system.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2009-2356

около 17 лет назад

Multiple stack-based buffer overflows in the pgsqlQuery function in NullLogic Groupware 1.2.7, when PostgreSQL is used, might allow remote attackers to execute arbitrary code via input to the (1) POP3, (2) SMTP, or (3) web component that triggers a long SQL query.

CVSS2: 9.3
EPSS: Низкий
nvd логотип

CVE-2009-2355

около 17 лет назад

The forum module in NullLogic Groupware 1.2.7 allows remote authenticated users to cause a denial of service (application crash) by specifying (1) an empty string or (2) a non-numeric string when selecting a forum, related to the fmessagelist function.

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2009-2354

около 17 лет назад

SQL injection vulnerability in the auth_checkpass function in the login page in NullLogic Groupware 1.2.7 allows remote attackers to execute arbitrary SQL commands via the username parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2009-2353

около 17 лет назад

encoder.php in eAccelerator allows remote attackers to execute arbitrary code by copying a local executable file to a location under the web root via the -o option, and then making a direct request to this file, related to upload of image files.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2009-2352

около 17 лет назад

Google Chrome 1.0.154.48 and earlier does not block javascript: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header or (2) specifying the content of a Refresh header, a related issue to CVE-2009-1312. NOTE: it was later reported that 2.0.172.28, 2.0.172.37, and 3.0.193.2 Beta are also affected.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2009-2351

около 17 лет назад

Opera 9.52 and earlier does not block javascript: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header or (2) specifying the content of a Refresh header, a related issue to CVE-2009-1312. NOTE: it was later reported that 10.00 Beta 3 Build 1699 is also affected.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2009-2350

около 17 лет назад

Microsoft Internet Explorer 6.0.2900.2180 and earlier does not block javascript: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header or (2) specifying the content of a Refresh header, a related issue to CVE-2009-1312.

CVSS2: 4.3
EPSS: Средний
nvd логотип

CVE-2009-2348

около 17 лет назад

Android 1.5 CRBxx allows local users to bypass the (1) Manifest.permission.CAMERA (aka android.permission.CAMERA) and (2) Manifest.permission.AUDIO_RECORD (aka android.permission.RECORD_AUDIO) configuration settings by installing and executing an application that does not make a permission request before using the camera or microphone.

CVSS2: 6.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2009-2368

Unspecified vulnerability in Socks Server 5 before 3.7.8-8 has unknown impact and attack vectors.

CVSS2: 10
1%
Низкий
около 17 лет назад
nvd логотип
CVE-2009-2367

cgi-bin/makecgi-pro in Iomega StorCenter Pro generates predictable session IDs, which allows remote attackers to hijack active sessions and gain privileges via brute force guessing attacks on the session_id parameter.

CVSS3: 9.8
23%
Средний
около 17 лет назад
nvd логотип
CVE-2009-2366

SQL injection vulnerability in login.asp in DataCheck Solutions ForumPal FE 1.1 and ForumPal 1.5 allows remote attackers to execute arbitrary SQL commands via the (1) password parameter in 1.1 and (2) p_password parameter in 1.5. NOTE: some of these details are obtained from third party information.

CVSS2: 7.5
1%
Низкий
около 17 лет назад
nvd логотип
CVE-2009-2365

SQL injection vulnerability in login.asp in DataCheck Solutions GalleryPal FE 1.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

CVSS2: 7.5
1%
Низкий
около 17 лет назад
nvd логотип
CVE-2009-2364

Stack-based buffer overflow in Mp3-Nator 2.0 allows remote attackers to execute arbitrary code via (1) a long string in a .plf file and (2) a long string in the listdata.dat file, possibly related to a track entry.

CVSS2: 9.3
10%
Средний
около 17 лет назад
nvd логотип
CVE-2009-2363

Stack-based buffer overflow in KUDRSOFT AudioPLUS 2.00.215 allows remote attackers to execute arbitrary code via a .pls playlist file with a playlist entry containing a long File1 argument.

CVSS2: 9.3
6%
Низкий
около 17 лет назад
nvd логотип
CVE-2009-2362

Stack-based buffer overflow in KUDRSOFT AudioPLUS 2.0.0.215 allows remote attackers to execute arbitrary code via a long string in a (1) .lst or (2) .m3u playlist file.

CVSS2: 9.3
7%
Низкий
около 17 лет назад
nvd логотип
CVE-2009-2361

SQL injection vulnerability in include/class.staff.php in osTicket before 1.6 RC5 allows remote attackers to execute arbitrary SQL commands via the staff username parameter.

CVSS2: 7.5
5%
Низкий
около 17 лет назад
nvd логотип
CVE-2009-2360

Cross-site scripting (XSS) vulnerability in passwd/main.php in the Passwd module before 3.1.1 for Horde allows remote attackers to inject arbitrary web script or HTML via the backend parameter.

CVSS2: 4.3
5%
Низкий
около 17 лет назад
nvd логотип
CVE-2009-2359

Multiple SQL injection vulnerabilities in TekRADIUS 3.0 allow context-dependent attackers to execute arbitrary SQL commands via (1) the GUI client, as demonstrated by input to the Browse Users text box in the Users tab; or (2) the command-line client, as demonstrated by a certain trcli -r command.

CVSS2: 7.5
1%
Низкий
около 17 лет назад
nvd логотип
CVE-2009-2358

TekRADIUS 3.0 uses BUILTIN\Users:R permissions for the TekRADIUS.ini file, which allows local users to obtain obfuscated database credentials by reading this file.

CVSS2: 4.6
0%
Низкий
около 17 лет назад
nvd логотип
CVE-2009-2357

The default configuration of TekRADIUS 3.0 uses the sa account to communicate with Microsoft SQL Server, which makes it easier for remote attackers to obtain privileged access to the database and the underlying Windows operating system.

CVSS2: 10
2%
Низкий
около 17 лет назад
nvd логотип
CVE-2009-2356

Multiple stack-based buffer overflows in the pgsqlQuery function in NullLogic Groupware 1.2.7, when PostgreSQL is used, might allow remote attackers to execute arbitrary code via input to the (1) POP3, (2) SMTP, or (3) web component that triggers a long SQL query.

CVSS2: 9.3
4%
Низкий
около 17 лет назад
nvd логотип
CVE-2009-2355

The forum module in NullLogic Groupware 1.2.7 allows remote authenticated users to cause a denial of service (application crash) by specifying (1) an empty string or (2) a non-numeric string when selecting a forum, related to the fmessagelist function.

CVSS2: 4
1%
Низкий
около 17 лет назад
nvd логотип
CVE-2009-2354

SQL injection vulnerability in the auth_checkpass function in the login page in NullLogic Groupware 1.2.7 allows remote attackers to execute arbitrary SQL commands via the username parameter.

CVSS2: 7.5
1%
Низкий
около 17 лет назад
nvd логотип
CVE-2009-2353

encoder.php in eAccelerator allows remote attackers to execute arbitrary code by copying a local executable file to a location under the web root via the -o option, and then making a direct request to this file, related to upload of image files.

CVSS2: 6.8
2%
Низкий
около 17 лет назад
nvd логотип
CVE-2009-2352

Google Chrome 1.0.154.48 and earlier does not block javascript: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header or (2) specifying the content of a Refresh header, a related issue to CVE-2009-1312. NOTE: it was later reported that 2.0.172.28, 2.0.172.37, and 3.0.193.2 Beta are also affected.

CVSS2: 4.3
2%
Низкий
около 17 лет назад
nvd логотип
CVE-2009-2351

Opera 9.52 and earlier does not block javascript: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header or (2) specifying the content of a Refresh header, a related issue to CVE-2009-1312. NOTE: it was later reported that 10.00 Beta 3 Build 1699 is also affected.

CVSS2: 4.3
2%
Низкий
около 17 лет назад
nvd логотип
CVE-2009-2350

Microsoft Internet Explorer 6.0.2900.2180 and earlier does not block javascript: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header or (2) specifying the content of a Refresh header, a related issue to CVE-2009-1312.

CVSS2: 4.3
14%
Средний
около 17 лет назад
nvd логотип
CVE-2009-2348

Android 1.5 CRBxx allows local users to bypass the (1) Manifest.permission.CAMERA (aka android.permission.CAMERA) and (2) Manifest.permission.AUDIO_RECORD (aka android.permission.RECORD_AUDIO) configuration settings by installing and executing an application that does not make a permission request before using the camera or microphone.

CVSS2: 6.9
0%
Низкий
около 17 лет назад

Уязвимостей на страницу