Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 386 296

Количество 386 296

nvd логотип

CVE-2009-2327

около 17 лет назад

Cross-site scripting (XSS) vulnerability in add_voting.php in KerviNet Forum 1.1 and earlier allows remote authenticated users to inject arbitrary web script or HTML via the v_variant1 parameter.

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2009-2326

около 17 лет назад

Multiple SQL injection vulnerabilities in KerviNet Forum 1.1 and earlier allow remote attackers to execute arbitrary SQL commands via (1) an enter_parol cookie to index.php in an auto action or (2) the topic parameter to message.php. NOTE: vector 2 can be leveraged for a cross-site scripting (XSS) attack.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2009-2325

около 17 лет назад

Directory traversal vulnerability in index.php in Clicknet CMS 2.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the side parameter.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2009-2324

около 17 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to inject arbitrary web script or HTML via components in the samples (aka _samples) directory.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2009-2323

около 17 лет назад

The web interface on the Axesstel MV 410R redirects users back to the referring page after execution of some CGI scripts, which makes it easier for remote attackers to avoid detection of cross-site request forgery (CSRF) attacks, as demonstrated by a redirect from the cgi-bin/wireless.cgi script.

CVSS2: 5.8
EPSS: Низкий
nvd логотип

CVE-2009-2322

около 17 лет назад

Cross-site scripting (XSS) vulnerability in cgi-bin/sysconf.cgi on the Axesstel MV 410R allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2009-2321

около 17 лет назад

cgi-bin/sysconf.cgi on the Axesstel MV 410R allows remote attackers to cause a denial of service (configuration reset) via a RESTORE=RESTORE query string.

CVSS2: 7.8
EPSS: Низкий
nvd логотип

CVE-2009-2320

около 17 лет назад

The web interface on the Axesstel MV 410R relies on client-side JavaScript code to validate input, which allows remote attackers to send crafted data, and possibly have unspecified other impact, via a client that does not process JavaScript.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2009-2319

около 17 лет назад

The default configuration of the Wi-Fi component on the Axesstel MV 410R does not use encryption, which makes it easier for remote attackers to obtain sensitive information by sniffing the network.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2009-2318

около 17 лет назад

The Axesstel MV 410R allows remote attackers to cause a denial of service via a flood of SYN packets, a related issue to CVE-1999-0116.

CVSS2: 7.8
EPSS: Низкий
nvd логотип

CVE-2009-2317

около 17 лет назад

The Axesstel MV 410R has a certain default administrator password, and does not force a password change, which makes it easier for remote attackers to obtain access.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2009-2316

около 17 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in IBM Tivoli Identity Manager (ITIM) 5.0 allow remote attackers to inject arbitrary web script or HTML by entering an unspecified URL in (1) the self-service UI interface or (2) the console interface. NOTE: it was later reported that 4.6.0 is also affected by the first vector.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2009-2315

около 17 лет назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2009-2204. Reason: This candidate is a duplicate of CVE-2009-2204. Notes: All CVE users should reference CVE-2009-2204 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

EPSS: Низкий
nvd логотип

CVE-2009-2314

около 17 лет назад

Race condition in the Sun Lightweight Availability Collection Tool 3.0 on Solaris 7 through 10 allows local users to overwrite arbitrary files via unspecified vectors.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2009-2313

около 17 лет назад

Directory traversal vulnerability in index.php in Jinzora Media Jukebox 2.8 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the name parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2009-2312

около 17 лет назад

SmartFilter Web Gateway Security 4.2.1.00 stores user credentials in cleartext in config.txt and uses insecure permissions for this file, which allows local users to gain privileges.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2009-2311

около 17 лет назад

SQL injection vulnerability in the rGallery plugin 1.2.3 for WoltLab Burning Board (WBB3) allows remote attackers to execute arbitrary SQL commands via the userID parameter in the RGalleryUserGallery page to index.php, a different vector than CVE-2008-4627.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2009-2310

около 17 лет назад

SQL injection vulnerability in include/get_read.php in Extensible-BioLawCom CMS (X-BLC) 0.2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the section parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2009-2309

около 17 лет назад

SQL injection vulnerability in index.php in Codice CMS 2 allows remote attackers to execute arbitrary SQL commands via the tag parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2009-2308

около 17 лет назад

Multiple SQL injection vulnerabilities in affiliates.php in the Affiliation (aka Affiliates) module 1.1.0 and earlier for PunBB allow remote attackers to execute arbitrary SQL commands via the (1) in or (2) out parameter.

CVSS2: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2009-2327

Cross-site scripting (XSS) vulnerability in add_voting.php in KerviNet Forum 1.1 and earlier allows remote authenticated users to inject arbitrary web script or HTML via the v_variant1 parameter.

CVSS2: 3.5
3%
Низкий
около 17 лет назад
nvd логотип
CVE-2009-2326

Multiple SQL injection vulnerabilities in KerviNet Forum 1.1 and earlier allow remote attackers to execute arbitrary SQL commands via (1) an enter_parol cookie to index.php in an auto action or (2) the topic parameter to message.php. NOTE: vector 2 can be leveraged for a cross-site scripting (XSS) attack.

CVSS2: 7.5
1%
Низкий
около 17 лет назад
nvd логотип
CVE-2009-2325

Directory traversal vulnerability in index.php in Clicknet CMS 2.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the side parameter.

CVSS2: 5
3%
Низкий
около 17 лет назад
nvd логотип
CVE-2009-2324

Multiple cross-site scripting (XSS) vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to inject arbitrary web script or HTML via components in the samples (aka _samples) directory.

CVSS2: 4.3
2%
Низкий
около 17 лет назад
nvd логотип
CVE-2009-2323

The web interface on the Axesstel MV 410R redirects users back to the referring page after execution of some CGI scripts, which makes it easier for remote attackers to avoid detection of cross-site request forgery (CSRF) attacks, as demonstrated by a redirect from the cgi-bin/wireless.cgi script.

CVSS2: 5.8
1%
Низкий
около 17 лет назад
nvd логотип
CVE-2009-2322

Cross-site scripting (XSS) vulnerability in cgi-bin/sysconf.cgi on the Axesstel MV 410R allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS2: 4.3
1%
Низкий
около 17 лет назад
nvd логотип
CVE-2009-2321

cgi-bin/sysconf.cgi on the Axesstel MV 410R allows remote attackers to cause a denial of service (configuration reset) via a RESTORE=RESTORE query string.

CVSS2: 7.8
2%
Низкий
около 17 лет назад
nvd логотип
CVE-2009-2320

The web interface on the Axesstel MV 410R relies on client-side JavaScript code to validate input, which allows remote attackers to send crafted data, and possibly have unspecified other impact, via a client that does not process JavaScript.

CVSS2: 7.5
1%
Низкий
около 17 лет назад
nvd логотип
CVE-2009-2319

The default configuration of the Wi-Fi component on the Axesstel MV 410R does not use encryption, which makes it easier for remote attackers to obtain sensitive information by sniffing the network.

CVSS2: 5
1%
Низкий
около 17 лет назад
nvd логотип
CVE-2009-2318

The Axesstel MV 410R allows remote attackers to cause a denial of service via a flood of SYN packets, a related issue to CVE-1999-0116.

CVSS2: 7.8
1%
Низкий
около 17 лет назад
nvd логотип
CVE-2009-2317

The Axesstel MV 410R has a certain default administrator password, and does not force a password change, which makes it easier for remote attackers to obtain access.

CVSS2: 10
2%
Низкий
около 17 лет назад
nvd логотип
CVE-2009-2316

Multiple cross-site scripting (XSS) vulnerabilities in IBM Tivoli Identity Manager (ITIM) 5.0 allow remote attackers to inject arbitrary web script or HTML by entering an unspecified URL in (1) the self-service UI interface or (2) the console interface. NOTE: it was later reported that 4.6.0 is also affected by the first vector.

CVSS2: 4.3
2%
Низкий
около 17 лет назад
nvd логотип
CVE-2009-2315

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2009-2204. Reason: This candidate is a duplicate of CVE-2009-2204. Notes: All CVE users should reference CVE-2009-2204 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

около 17 лет назад
nvd логотип
CVE-2009-2314

Race condition in the Sun Lightweight Availability Collection Tool 3.0 on Solaris 7 through 10 allows local users to overwrite arbitrary files via unspecified vectors.

CVSS2: 2.1
0%
Низкий
около 17 лет назад
nvd логотип
CVE-2009-2313

Directory traversal vulnerability in index.php in Jinzora Media Jukebox 2.8 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the name parameter.

CVSS2: 7.5
2%
Низкий
около 17 лет назад
nvd логотип
CVE-2009-2312

SmartFilter Web Gateway Security 4.2.1.00 stores user credentials in cleartext in config.txt and uses insecure permissions for this file, which allows local users to gain privileges.

CVSS2: 4.6
0%
Низкий
около 17 лет назад
nvd логотип
CVE-2009-2311

SQL injection vulnerability in the rGallery plugin 1.2.3 for WoltLab Burning Board (WBB3) allows remote attackers to execute arbitrary SQL commands via the userID parameter in the RGalleryUserGallery page to index.php, a different vector than CVE-2008-4627.

CVSS2: 7.5
1%
Низкий
около 17 лет назад
nvd логотип
CVE-2009-2310

SQL injection vulnerability in include/get_read.php in Extensible-BioLawCom CMS (X-BLC) 0.2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the section parameter.

CVSS2: 7.5
1%
Низкий
около 17 лет назад
nvd логотип
CVE-2009-2309

SQL injection vulnerability in index.php in Codice CMS 2 allows remote attackers to execute arbitrary SQL commands via the tag parameter.

CVSS2: 7.5
1%
Низкий
около 17 лет назад
nvd логотип
CVE-2009-2308

Multiple SQL injection vulnerabilities in affiliates.php in the Affiliation (aka Affiliates) module 1.1.0 and earlier for PunBB allow remote attackers to execute arbitrary SQL commands via the (1) in or (2) out parameter.

CVSS2: 7.5
1%
Низкий
около 17 лет назад

Уязвимостей на страницу