2009 CVE Vulnerabilities

5,054 CVEs published in 2009.

CVE IDSeverityCVSSDescription
CVE-2009-2361SQL injection vulnerability in include/class.staff.php in osTicket before 1.6 RC5 allows remote attackers to execute arb...
CVE-2009-2360Cross-site scripting (XSS) vulnerability in passwd/main.php in the Passwd module before 3.1.1 for Horde allows remote at...
CVE-2009-2359Multiple SQL injection vulnerabilities in TekRADIUS 3.0 allow context-dependent attackers to execute arbitrary SQL comma...
CVE-2009-2358TekRADIUS 3.0 uses BUILTIN\Users:R permissions for the TekRADIUS.ini file, which allows local users to obtain obfuscated...
CVE-2009-2357The default configuration of TekRADIUS 3.0 uses the sa account to communicate with Microsoft SQL Server, which makes it ...
CVE-2009-2356Multiple stack-based buffer overflows in the pgsqlQuery function in NullLogic Groupware 1.2.7, when PostgreSQL is used, ...
CVE-2009-2355The forum module in NullLogic Groupware 1.2.7 allows remote authenticated users to cause a denial of service (applicatio...
CVE-2009-2354SQL injection vulnerability in the auth_checkpass function in the login page in NullLogic Groupware 1.2.7 allows remote ...
CVE-2009-2353encoder.php in eAccelerator allows remote attackers to execute arbitrary code by copying a local executable file to a lo...
CVE-2009-2352Google Chrome 1.0.154.48 and earlier does not block javascript: URIs in Refresh headers in HTTP responses, which allows ...
CVE-2009-2351Opera 9.52 and earlier does not block javascript: URIs in Refresh headers in HTTP responses, which allows remote attacke...
CVE-2009-2350Microsoft Internet Explorer 6.0.2900.2180 and earlier does not block javascript: URIs in Refresh headers in HTTP respons...
CVE-2009-2345Multiple SQL injection vulnerabilities in ClanSphere before 2009.0.1 allow remote attackers to execute arbitrary SQL com...
CVE-2009-2344The web-based management interfaces in Sourcefire Defense Center (DC) and 3D Sensor before 4.8.2 allow remote authentica...
CVE-2009-2343Cross-site scripting (XSS) vulnerability in people.php in Zoph before 0.7.0.6 allows remote attackers to inject arbitrar...
CVE-2009-2342Cross-site scripting (XSS) vulnerability in admin.php (aka the login page) in Content Management Made Easy (CMME) before...
CVE-2009-2341SQL injection vulnerability in albumdetail.php in Opial 1.0 allows remote attackers to execute arbitrary SQL commands vi...
CVE-2009-2340SQL injection vulnerability in admin/index.php in Opial 1.0 allows remote attackers to execute arbitrary SQL commands vi...
CVE-2009-2339SQL injection vulnerability in index.php in Rentventory allows remote attackers to execute arbitrary SQL commands via th...
CVE-2009-2338Directory traversal vulnerability in includes/startmodules.inc.php in FreeWebshop.org 2.2.9 R2, when register_globals is...
CVE-2009-2337SQL injection vulnerability in includes/module/book/index.inc.php in w3b|cms Gaestebuch Guestbook Module 3.0.0, when mag...
CVE-2009-2333Multiple directory traversal vulnerabilities in CMS Chainuk 1.2 and earlier allow remote attackers to include and execut...
CVE-2009-2332CMS Chainuk 1.2 and earlier allows remote attackers to obtain sensitive information via (1) a crafted id parameter to in...
CVE-2009-2331Multiple static code injection vulnerabilities in CMS Chainuk 1.2 and earlier allow remote attackers to inject arbitrary...
CVE-2009-2330Cross-site scripting (XSS) vulnerability in admin/admin_menu.php in CMS Chainuk 1.2 and earlier allows remote attackers ...

Check if your code is affected by 2009 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now