2009 CVE Vulnerabilities

5,054 CVEs published in 2009.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2009-2343——Cross-site scripting (XSS) vulnerability in people.php in Zoph before 0.7.0.6 allows remote attackers to inject arbitrar...
CVE-2009-2342——Cross-site scripting (XSS) vulnerability in admin.php (aka the login page) in Content Management Made Easy (CMME) before...
CVE-2009-2341——SQL injection vulnerability in albumdetail.php in Opial 1.0 allows remote attackers to execute arbitrary SQL commands vi...
CVE-2009-2340——SQL injection vulnerability in admin/index.php in Opial 1.0 allows remote attackers to execute arbitrary SQL commands vi...
CVE-2009-2339——SQL injection vulnerability in index.php in Rentventory allows remote attackers to execute arbitrary SQL commands via th...
CVE-2009-2338——Directory traversal vulnerability in includes/startmodules.inc.php in FreeWebshop.org 2.2.9 R2, when register_globals is...
CVE-2009-2337——SQL injection vulnerability in includes/module/book/index.inc.php in w3b|cms Gaestebuch Guestbook Module 3.0.0, when mag...
CVE-2009-2333——Multiple directory traversal vulnerabilities in CMS Chainuk 1.2 and earlier allow remote attackers to include and execut...
CVE-2009-2332——CMS Chainuk 1.2 and earlier allows remote attackers to obtain sensitive information via (1) a crafted id parameter to in...
CVE-2009-2331——Multiple static code injection vulnerabilities in CMS Chainuk 1.2 and earlier allow remote attackers to inject arbitrary...
CVE-2009-2330——Cross-site scripting (XSS) vulnerability in admin/admin_menu.php in CMS Chainuk 1.2 and earlier allows remote attackers ...
CVE-2009-2329——KerviNet Forum 1.1 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) admin...
CVE-2009-2328——admin/edit_user.php in KerviNet Forum 1.1 and earlier does not require administrative authentication, which allows remot...
CVE-2009-2327——Cross-site scripting (XSS) vulnerability in add_voting.php in KerviNet Forum 1.1 and earlier allows remote authenticated...
CVE-2009-2326——Multiple SQL injection vulnerabilities in KerviNet Forum 1.1 and earlier allow remote attackers to execute arbitrary SQL...
CVE-2009-2325——Directory traversal vulnerability in index.php in Clicknet CMS 2.1 allows remote attackers to read arbitrary files via a...
CVE-2009-2324——Multiple cross-site scripting (XSS) vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to inject arbitra...
CVE-2009-2323——The web interface on the Axesstel MV 410R redirects users back to the referring page after execution of some CGI scripts...
CVE-2009-2322——Cross-site scripting (XSS) vulnerability in cgi-bin/sysconf.cgi on the Axesstel MV 410R allows remote attackers to injec...
CVE-2009-2321——cgi-bin/sysconf.cgi on the Axesstel MV 410R allows remote attackers to cause a denial of service (configuration reset) v...
CVE-2009-2320——The web interface on the Axesstel MV 410R relies on client-side JavaScript code to validate input, which allows remote a...
CVE-2009-2319——The default configuration of the Wi-Fi component on the Axesstel MV 410R does not use encryption, which makes it easier ...
CVE-2009-2318——The Axesstel MV 410R allows remote attackers to cause a denial of service via a flood of SYN packets, a related issue to...
CVE-2009-2317——The Axesstel MV 410R has a certain default administrator password, and does not force a password change, which makes it ...
CVE-2009-2316——Multiple cross-site scripting (XSS) vulnerabilities in IBM Tivoli Identity Manager (ITIM) 5.0 allow remote attackers to ...

Check if your code is affected by 2009 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now