VYPR

CVEs

385,520 total · page 6939 of 7,711

  • CVE-2009-3361Sep 24, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in index.php in PHP-IPNMonitor allows remote attackers to execute arbitrary SQL commands via the maincat_id parameter.

  • CVE-2009-3360Sep 24, 2009
    risk 0.03cvss —epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in Datemill 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) return parameter to photo_view.php, and st parameter to (2) photo_search.php and (3) search.php.

  • CVE-2009-3359Sep 24, 2009
    risk 0.03cvss —epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in Match Agency BiZ 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) important parameter to edit_profile.php and (2) pid parameter to report.php.

  • CVE-2009-3358Sep 24, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in profile.php in Tourism Scripts Adult Portal escort listing allows remote attackers to execute arbitrary SQL commands via the user_id parameter.

  • CVE-2009-3357Sep 24, 2009
    risk 0.03cvss —epss 0.01

    Multiple SQL injection vulnerabilities in the Hotel Booking Reservation System (aka HBS or com_hbssearch) component for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) h_id, (2) id, and (3) rid parameters to longDesc.php, and the h_id parameter to…

  • CVE-2009-3356Sep 24, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in index.php in Image voting 1.0 allows remote attackers to execute arbitrary SQL commands via the show parameter.

  • CVE-2009-3355Sep 24, 2009
    risk 0.03cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in profile.php in Datetopia Buy Dating Site 1.0 allows remote attackers to inject arbitrary web script or HTML via the s_r parameter.

  • CVE-2009-3354Sep 24, 2009
    risk 0.00cvss —epss 0.01

    Multiple unspecified vulnerabilities in the Rest API module for Drupal have unknown impact and attack vectors.

  • CVE-2009-3353Sep 24, 2009
    risk 0.00cvss —epss 0.01

    Multiple unspecified vulnerabilities in the Node2Node module for Drupal have unknown impact and attack vectors.

  • CVE-2009-3352Sep 24, 2009
    risk 0.00cvss —epss 0.02

    Multiple unspecified vulnerabilities in the quota_by_role (Quota by role) module for Drupal have unknown impact and attack vectors.

  • CVE-2009-3351Sep 24, 2009
    risk 0.00cvss —epss 0.01

    Multiple unspecified vulnerabilities in the Node Browser module for Drupal have unknown impact and attack vectors.

  • CVE-2009-3350Sep 24, 2009
    risk 0.00cvss —epss 0.01

    Multiple unspecified vulnerabilities in the Subdomain Manager module for Drupal have unknown impact and attack vectors.

  • CVE-2009-3349Sep 24, 2009
    risk 0.03cvss —epss 0.02

    SQL injection vulnerability in Datavore Gyro 5.0 allows remote attackers to execute arbitrary SQL commands via the cid parameter in a cat action to the home component.

  • CVE-2009-3348Sep 24, 2009
    risk 0.03cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in Datavore Gyro 5.0 allows remote attackers to inject arbitrary web script or HTML via the cid parameter in a cat action to the home component.

  • CVE-2009-3347Sep 24, 2009
    risk 0.00cvss —epss 0.04

    Buffer overflow on the D-Link DIR-400 wireless router allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.10 through 8.11. NOTE: as of 20090917, this disclosure has no actionable…

  • CVE-2009-3346Sep 24, 2009
    risk 0.00cvss —epss 0.04

    Unspecified vulnerability in SAP Crystal Reports Server 2008 allows remote attackers to execute arbitrary code via unknown vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.3 through 8.11. NOTE: as of 20090917, this disclosure has no actionable…

  • CVE-2009-3345Sep 24, 2009
    risk 0.00cvss —epss 0.02

    Heap-based buffer overflow in SAP Crystal Reports Server 2008 has unknown impact and attack vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.3 through 8.11. NOTE: as of 20090917, this disclosure has no actionable information. However, because the…

  • CVE-2009-3344Sep 24, 2009
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in SAP Crystal Reports Server 2008 on Windows XP allows attackers to cause a denial of service (infinite loop) via unknown vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.3 through 8.11. NOTE: as of 20090917, this…

  • CVE-2009-3343Sep 24, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in details.asp in HotWeb Rentals allows remote attackers to execute arbitrary SQL commands via the PropId parameter.

  • CVE-2009-3342Sep 24, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in frontend/assets/ajax/checkusername.php in the AlphaUserPoints (com_alphauserpoints) component 1.5.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the username2points parameter.

  • CVE-2009-3341Sep 24, 2009
    risk 0.00cvss —epss 0.05

    Buffer overflow on the Linksys WRT54GL wireless router allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.10 through 8.11. NOTE: as of 20090917, this disclosure has no actionable…

  • CVE-2009-3340Sep 24, 2009
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in FreeSSHD 1.2.4 allows remote attackers to cause a denial of service via unknown vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.11. NOTE: as of 20090917, this disclosure has no actionable information. However, because…

  • CVE-2009-3339Sep 24, 2009
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in McAfee Email and Web Security Appliance 5.1 VMtrial allows remote attackers to read arbitrary files via unknown vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.9 through 8.11. NOTE: as of 20090917, this disclosure has…

  • CVE-2009-3338Sep 24, 2009
    risk 0.03cvss —epss 0.06

    Stack-based buffer overflow in EffectMatrix (E.M.) Magic Morph 1.95b allows remote attackers to execute arbitrary code via a long string in a .mor file.

  • CVE-2009-3337Sep 24, 2009
    risk 0.00cvss —epss 0.01

    SQL injection vulnerability in the Freetag (serendipity_event_freetag) plugin before 3.09 for Serendipity (S9Y) allows remote attackers to execute arbitrary SQL commands via an unspecified parameter associated with Meta keywords in a blog entry.

  • CVE-2009-3336Sep 24, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in auction_details.php in PHP Pro Bid allows remote attackers to execute arbitrary SQL commands via the auction_id parameter.

  • CVE-2009-3335Sep 24, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the TurtuShout component 0.11 for Joomla! allows remote attackers to execute arbitrary SQL commands via the Name field.

  • CVE-2009-2680Sep 24, 2009
    risk 0.00cvss —epss 0.03

    Unspecified vulnerability in the Remote Management Interface (RMI) for MSL Tape Libraries and 1/8 G2 Tape Autoloaders in HP StorageWorks 1/8 G2 Tape Autoloader firmware 2.30 and earlier, MSL2024 Tape Library firmware 4.20 and earlier, MSL4048 Tape Library firmware 6.50 and…

  • CVE-2009-3334Sep 23, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the Lhacky! Extensions Cave Joomla! Integrated Newsletters Component (aka JINC or com_jinc) component 0.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the newsid parameter in a messages action to index.php.

  • CVE-2009-3333Sep 23, 2009
    risk 0.03cvss —epss 0.02

    PHP remote file inclusion vulnerability in koesubmit.php in the koeSubmit (com_koesubmit) component 1.0 for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

  • CVE-2009-3332Sep 23, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the JBudgetsMagic (com_jbudgetsmagic) component 0.3.2 through 0.4.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the bid parameter in a mybudget action to index.php.

  • CVE-2009-3331Sep 23, 2009
    risk 0.03cvss —epss 0.02

    Multiple PHP remote file inclusion vulnerabilities in DDL CMS 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the wwwRoot parameter to (1) header.php, (2) submit.php, (3) submitted.php, and (4) autosubmitter/index.php.

  • CVE-2009-3330Sep 23, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in index.php in cP Creator 2.7.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the tickets parameter in a support ticket action.

  • CVE-2009-3329Sep 23, 2009
    risk 0.00cvss —epss 0.04

    Stack-based buffer overflow in Winplot 1.25.0.1 allows user-assisted remote attackers to execute arbitrary code via a crafted Plot2D (.wp2) file.

  • CVE-2009-3328Sep 23, 2009
    risk 0.03cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in sign.php in WX-Guestbook 1.1.208 allows remote attackers to inject arbitrary web script or HTML via the sName parameter (aka the name field). NOTE: some of these details are obtained from third party information.

  • CVE-2009-3327Sep 23, 2009
    risk 0.03cvss —epss 0.01

    Multiple SQL injection vulnerabilities in WX-Guestbook 1.1.208 allow remote attackers to execute arbitrary SQL commands via the (1) QUERY parameter to search.php and (2) USERNAME parameter to login.php. NOTE: some of these details are obtained from third party information.

  • CVE-2009-3326Sep 23, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in index.php in CMScontrol Content Management System 7.x allows remote attackers to execute arbitrary SQL commands via the id_menu parameter.

  • CVE-2009-3325Sep 23, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the Focusplus Developments Survey Manager (com_surveymanager) component 1.5.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the stype parameter in an editsurvey action to index.php.

  • CVE-2009-3324Sep 23, 2009
    risk 0.03cvss —epss 0.02

    PHP remote file inclusion vulnerability in include/prodler.class.php in ProdLer 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the sPath parameter.

  • CVE-2009-3323Sep 23, 2009
    risk 0.03cvss —epss 0.02

    Multiple PHP remote file inclusion vulnerabilities in BAnner ROtation System mini (BAROSmini) 0.32.595 allow remote attackers to execute arbitrary PHP code via a URL in the baros_path parameter to (1) include/common_functions.php, and the main_path parameter to (2)…

  • CVE-2009-3322Sep 23, 2009
    risk 0.03cvss —epss 0.03

    The Siemens Gigaset SE361 WLAN router allows remote attackers to cause a denial of service (device reboot) via a flood of crafted TCP packets to port 1723.

  • CVE-2009-3321Sep 23, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in SaphpLesson 4.3, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the CLIENT_IP HTTP header.

  • CVE-2009-3320Sep 23, 2009
    risk 0.03cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in scrivi.php in Zenas PaoLink (aka Pao-Link) 1.0 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.

  • CVE-2009-3319Sep 23, 2009
    risk 0.00cvss —epss 0.01

    SQL injection vulnerability in poems.php in DCI-Designs Dawaween 1.03 allows remote attackers to execute arbitrary SQL commands via the id parameter in a sec list action, a different vector than CVE-2006-1018.

  • CVE-2009-3318Sep 23, 2009
    risk 0.04cvss —epss 0.06

    Directory traversal vulnerability in the Roland Breedveld Album (com_album) component 1.14 for Joomla! allows remote attackers to access arbitrary directories and have unspecified other impact via a .. (dot dot) in the target parameter to index.php.

  • CVE-2009-3317Sep 23, 2009
    risk 0.03cvss —epss 0.03

    PHP remote file inclusion vulnerability in pages/pageHeader.php in OpenSiteAdmin 0.9.7 BETA allows remote attackers to execute arbitrary PHP code via a URL in the path parameter, a different vector than CVE-2008-0648.

  • CVE-2009-3316Sep 23, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the JReservation (com_jreservation) component 1.0 and 1.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the pid parameter in a propertycpanel action to index.php.

  • CVE-2009-3315Sep 23, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in admin/index.php in NeLogic Nephp Publisher Enterprise 3.5.9 and 4.5 allows remote attackers to execute arbitrary SQL commands via the Username field.

  • CVE-2009-3314Sep 23, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in ladders.php in Elite Gaming Ladders 3.2 allows remote attackers to execute arbitrary SQL commands via the platform parameter.

  • CVE-2009-3313Sep 23, 2009
    risk 0.03cvss —epss 0.01

    Multiple SQL injection vulnerabilities in FMyClone 2.3 allow remote attackers to execute arbitrary SQL commands via the comp parameter to (1) index.php and (2) editComments.php, and (3) allow remote authenticated administrators to execute arbitrary SQL commands via the id…