Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 386 296

Количество 386 296

nvd логотип

CVE-2009-1661

больше 17 лет назад

SQL injection vulnerability in admin/utopic.php in uTopic 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the rating parameter to index.php.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2009-1660

больше 17 лет назад

Stack-based buffer overflow in URUWorks ViPlay3 3.0 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long file entry in a .vpl file.

CVSS2: 9.3
EPSS: Низкий
nvd логотип

CVE-2009-1659

больше 17 лет назад

Unrestricted file upload vulnerability in admin/uploadimage.php in eLitius 1.0 allows remote attackers to bypass intended access restrictions and upload and execute arbitrary files via an avatar file with an accepted Content-Type such as image/gif, then requesting the file in admin/banners/.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2009-1658

больше 17 лет назад

Multiple SQL injection vulnerabilities in admin/admin.php in Realty Webware Technologies Realty Web-Base 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) user (username) and (2) password parameters. NOTE: some of these details are obtained from third party information.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2009-1657

больше 17 лет назад

Multiple SQL injection vulnerabilities in the Starrating plugin before 0.7.7 for b2evolution allow remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2009-1656

больше 17 лет назад

Xerox WorkCentre and WorkCentre Pro 232, 238, 245, 255, 265, 275; and WorkCentre 5632, 5638, 5645, 5655, 5665, 5675, 5687, 7655, 7656, and 7675 allows remote attackers to execute arbitrary commands via unknown attack vectors, aka "command injection vulnerability."

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2009-1655

больше 17 лет назад

Multiple SQL injection vulnerabilities in myaccount.php in Easy Scripts Answer and Question Script allow remote authenticated users to execute arbitrary SQL commands via the (1) user name (userid parameter) and (2) password.

CVSS2: 6.5
EPSS: Низкий
nvd логотип

CVE-2009-1654

больше 17 лет назад

Cross-site scripting (XSS) vulnerability in questiondetail.php in Easy Scripts Answer and Question Script allows remote attackers to inject arbitrary web script or HTML via the questionid parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2009-1653

больше 17 лет назад

Directory traversal vulnerability in examples/tbs_us_examples_0view.php in TinyButStrong 3.4.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the script parameter.

CVSS2: 7.8
EPSS: Низкий
nvd логотип

CVE-2009-1652

больше 17 лет назад

admin/adminaddeditdetails.php in Business Community Script does not properly restrict access, which allows remote attackers to gain privileges and add administrators via a direct request.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2009-1651

больше 17 лет назад

SQL injection vulnerability in admin/member_details.php in 2daybiz Business Community Script allows remote attackers to execute arbitrary SQL commands via the mid parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2009-1650

больше 17 лет назад

Multiple SQL injection vulnerabilities in photos.php in Shutter 0.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) albumID, (2) tagID, and (3) photoID parameters to index.html.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2009-1649

больше 17 лет назад

Directory traversal vulnerability in arch.php in beLive 0.2.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the arch parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2009-1648

около 17 лет назад

The YaST2 LDAP module in yast2-ldap-server on SUSE Linux Enterprise Server 11 (aka SLE11) does not enable the firewall in certain circumstances involving reboots during online updates, which makes it easier for remote attackers to access network services.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2009-1647

больше 17 лет назад

Heap-based buffer overflow in popcorn.exe in Ultrafunk Popcorn 1.87 allows remote POP3 servers to cause a denial of service (application crash) via a long string in a +OK response. NOTE: some of these details are obtained from third party information.

CVSS2: 9.3
EPSS: Низкий
nvd логотип

CVE-2009-1646

больше 17 лет назад

Stack-based buffer overflow in Mini-stream RM Downloader 3.0.0.9 allows remote attackers to execute arbitrary code via a long rtsp URL in a .ram file.

CVSS2: 9.3
EPSS: Низкий
nvd логотип

CVE-2009-1645

больше 17 лет назад

Multiple stack-based buffer overflows in Mini-stream Easy RM-MP3 Converter 3.0.0.7 allow remote attackers to execute arbitrary code via (1) a long rtsp URL in a .ram file and (2) a long string in the HREF attribute of a REF element in a .asx file.

CVSS2: 9.3
EPSS: Низкий
nvd логотип

CVE-2009-1644

больше 17 лет назад

Stack-based buffer overflow in Sorinara Streaming Audio Player 0.9 allows remote attackers to execute arbitrary code via a crafted .pla file.

CVSS2: 9.3
EPSS: Низкий
nvd логотип

CVE-2009-1643

больше 17 лет назад

Stack-based buffer overflow in Sorinara Soritong MP3 Player 1.0 allows remote attackers to execute arbitrary code via a crafted .m3u file.

CVSS2: 9.3
EPSS: Низкий
nvd логотип

CVE-2009-1642

больше 17 лет назад

Multiple stack-based buffer overflows in Mini-stream ASX to MP3 Converter 3.0.0.7 allow remote attackers to execute arbitrary code via (1) a long rtsp URL in a .ram file and (2) a long string in the HREF attribute of a REF element in a .asx file. NOTE: the latter was also subsequently reported in "prior to 3.1.3.7."

CVSS2: 9.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2009-1661

SQL injection vulnerability in admin/utopic.php in uTopic 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the rating parameter to index.php.

CVSS2: 6.8
1%
Низкий
больше 17 лет назад
nvd логотип
CVE-2009-1660

Stack-based buffer overflow in URUWorks ViPlay3 3.0 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long file entry in a .vpl file.

CVSS2: 9.3
6%
Низкий
больше 17 лет назад
nvd логотип
CVE-2009-1659

Unrestricted file upload vulnerability in admin/uploadimage.php in eLitius 1.0 allows remote attackers to bypass intended access restrictions and upload and execute arbitrary files via an avatar file with an accepted Content-Type such as image/gif, then requesting the file in admin/banners/.

CVSS2: 6.8
2%
Низкий
больше 17 лет назад
nvd логотип
CVE-2009-1658

Multiple SQL injection vulnerabilities in admin/admin.php in Realty Webware Technologies Realty Web-Base 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) user (username) and (2) password parameters. NOTE: some of these details are obtained from third party information.

CVSS2: 7.5
2%
Низкий
больше 17 лет назад
nvd логотип
CVE-2009-1657

Multiple SQL injection vulnerabilities in the Starrating plugin before 0.7.7 for b2evolution allow remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVSS2: 7.5
1%
Низкий
больше 17 лет назад
nvd логотип
CVE-2009-1656

Xerox WorkCentre and WorkCentre Pro 232, 238, 245, 255, 265, 275; and WorkCentre 5632, 5638, 5645, 5655, 5665, 5675, 5687, 7655, 7656, and 7675 allows remote attackers to execute arbitrary commands via unknown attack vectors, aka "command injection vulnerability."

CVSS2: 10
4%
Низкий
больше 17 лет назад
nvd логотип
CVE-2009-1655

Multiple SQL injection vulnerabilities in myaccount.php in Easy Scripts Answer and Question Script allow remote authenticated users to execute arbitrary SQL commands via the (1) user name (userid parameter) and (2) password.

CVSS2: 6.5
2%
Низкий
больше 17 лет назад
nvd логотип
CVE-2009-1654

Cross-site scripting (XSS) vulnerability in questiondetail.php in Easy Scripts Answer and Question Script allows remote attackers to inject arbitrary web script or HTML via the questionid parameter.

CVSS2: 4.3
1%
Низкий
больше 17 лет назад
nvd логотип
CVE-2009-1653

Directory traversal vulnerability in examples/tbs_us_examples_0view.php in TinyButStrong 3.4.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the script parameter.

CVSS2: 7.8
3%
Низкий
больше 17 лет назад
nvd логотип
CVE-2009-1652

admin/adminaddeditdetails.php in Business Community Script does not properly restrict access, which allows remote attackers to gain privileges and add administrators via a direct request.

CVSS2: 7.5
6%
Низкий
больше 17 лет назад
nvd логотип
CVE-2009-1651

SQL injection vulnerability in admin/member_details.php in 2daybiz Business Community Script allows remote attackers to execute arbitrary SQL commands via the mid parameter.

CVSS2: 7.5
2%
Низкий
больше 17 лет назад
nvd логотип
CVE-2009-1650

Multiple SQL injection vulnerabilities in photos.php in Shutter 0.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) albumID, (2) tagID, and (3) photoID parameters to index.html.

CVSS2: 7.5
1%
Низкий
больше 17 лет назад
nvd логотип
CVE-2009-1649

Directory traversal vulnerability in arch.php in beLive 0.2.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the arch parameter.

CVSS2: 7.5
2%
Низкий
больше 17 лет назад
nvd логотип
CVE-2009-1648

The YaST2 LDAP module in yast2-ldap-server on SUSE Linux Enterprise Server 11 (aka SLE11) does not enable the firewall in certain circumstances involving reboots during online updates, which makes it easier for remote attackers to access network services.

CVSS2: 7.5
2%
Низкий
около 17 лет назад
nvd логотип
CVE-2009-1647

Heap-based buffer overflow in popcorn.exe in Ultrafunk Popcorn 1.87 allows remote POP3 servers to cause a denial of service (application crash) via a long string in a +OK response. NOTE: some of these details are obtained from third party information.

CVSS2: 9.3
3%
Низкий
больше 17 лет назад
nvd логотип
CVE-2009-1646

Stack-based buffer overflow in Mini-stream RM Downloader 3.0.0.9 allows remote attackers to execute arbitrary code via a long rtsp URL in a .ram file.

CVSS2: 9.3
5%
Низкий
больше 17 лет назад
nvd логотип
CVE-2009-1645

Multiple stack-based buffer overflows in Mini-stream Easy RM-MP3 Converter 3.0.0.7 allow remote attackers to execute arbitrary code via (1) a long rtsp URL in a .ram file and (2) a long string in the HREF attribute of a REF element in a .asx file.

CVSS2: 9.3
7%
Низкий
больше 17 лет назад
nvd логотип
CVE-2009-1644

Stack-based buffer overflow in Sorinara Streaming Audio Player 0.9 allows remote attackers to execute arbitrary code via a crafted .pla file.

CVSS2: 9.3
6%
Низкий
больше 17 лет назад
nvd логотип
CVE-2009-1643

Stack-based buffer overflow in Sorinara Soritong MP3 Player 1.0 allows remote attackers to execute arbitrary code via a crafted .m3u file.

CVSS2: 9.3
6%
Низкий
больше 17 лет назад
nvd логотип
CVE-2009-1642

Multiple stack-based buffer overflows in Mini-stream ASX to MP3 Converter 3.0.0.7 allow remote attackers to execute arbitrary code via (1) a long rtsp URL in a .ram file and (2) a long string in the HREF attribute of a REF element in a .asx file. NOTE: the latter was also subsequently reported in "prior to 3.1.3.7."

CVSS2: 9.3
7%
Низкий
больше 17 лет назад

Уязвимостей на страницу