2009 CVE Vulnerabilities

5,054 CVEs published in 2009.

CVE IDSeverityCVSSDescription
CVE-2009-4961Lanai Core 0.6 allows remote attackers to obtain configuration information via a direct request to info.php, which calls...
CVE-2009-4960Directory traversal vulnerability in modules/backup/download.php in Lanai Core 0.6 allows remote attackers to read arbit...
CVE-2009-4959SQL injection vulnerability in the T3M E-Mail Marketing Tool (t3m) extension 0.2.4 and earlier for TYPO3 allows remote a...
CVE-2009-4958SQL injection vulnerability in video.php in EMO Breeder Manager (aka EMO Breader Manager) allows remote attackers to exe...
CVE-2009-4957Directory traversal vulnerability in loadpanel.php in Interspire ActiveKB allows remote attackers to read arbitrary file...
CVE-2009-4956Cross-site scripting (XSS) vulnerability in the Visitor Tracking (ws_stats) extension before 0.1.2 for TYPO3 allows remo...
CVE-2009-4955SQL injection vulnerability in the ultraCards (th_ultracards) extension before 0.5.1 for TYPO3 allows remote attackers t...
CVE-2009-4954SQL injection vulnerability in the Versatile Calendar Extension [VCE] (sk_calendar) extension before 0.3.4 for TYPO3 all...
CVE-2009-4953Cross-site scripting (XSS) vulnerability in the Userdata Create/Edit (sg_userdata) extension before 0.91.0 for TYPO3 all...
CVE-2009-4952Directory traversal vulnerability in the Directory Listing (dir_listing) extension 1.1.0 and earlier for TYPO3 allows re...
CVE-2009-4951Unspecified vulnerability in the ClickStream Analyzer [output] (alternet_csa_out) extension 0.3.0 and earlier for TYPO3 ...
CVE-2009-4950SQL injection vulnerability in the A21glossary Advanced Output (a21glossary_advanced_output) extension before 0.1.12 for...
CVE-2009-4949SQL injection vulnerability in the Store Locator extension before 1.2.8 for TYPO3 allows remote attackers to execute arb...
CVE-2009-4948Cross-site scripting (XSS) vulnerability in the Store Locator extension before 1.2.8 for TYPO3 allows remote attackers t...
CVE-2009-4947SQL injection vulnerability in frmLoginPwdReminderPopup.aspx in Q2 Solutions ConnX 4.0.20080606 allows remote attackers ...
CVE-2009-4946Directory traversal vulnerability in the Messaging (com_messaging) component before 1.5.1 for Joomla! allows remote atta...
CVE-2009-4945AdPeeps 8.5d1 has a default password of admin for the admin account, which makes it easier for remote attackers to obtai...
CVE-2009-4944Multiple cross-site scripting (XSS) vulnerabilities in ATRC ACollab 1.2 allow remote attackers to inject arbitrary web s...
CVE-2009-4943index.php in AdPeeps 8.5d1 allows remote attackers to obtain sensitive information via (1) a view_adrates action with an...
CVE-2009-4942Cross-site request forgery (CSRF) vulnerability in ACollab 1.2 allows remote attackers to hijack the authentication of a...
CVE-2009-4941Cross-site scripting (XSS) vulnerability in sign_in.php in ATRC ACollab 1.2 allows remote attackers to inject arbitrary ...
CVE-2009-4940SQL injection vulnerability in index.php in Zeus Cart 2.3 and earlier allows remote attackers to execute arbitrary SQL c...
CVE-2009-4939Multiple cross-site scripting (XSS) vulnerabilities in index.php in AdPeeps 8.5d1 allow remote attackers to inject arbit...
CVE-2009-4938SQL injection vulnerability in the JVideo! (com_jvideo) component 0.3.11c Beta and 0.3.x for Joomla! allows remote attac...
CVE-2009-4937Cross-site scripting (XSS) vulnerability in Small Pirate (SPirate) 2.1 allows remote attackers to inject arbitrary web s...

Check if your code is affected by 2009 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now