2009 CVE Vulnerabilities

5,054 CVEs published in 2009.

CVE IDSeverityCVSSDescription
CVE-2009-4813——Cross-site scripting (XSS) vulnerability in myps.php in MyBB (aka MyBulletinBoard) 1.4.10 allows remote attackers to inj...
CVE-2009-4812——Wolfram Research webMathematica allows remote attackers to obtain sensitive information via a direct request to the MSP ...
CVE-2009-4811——VMware Authentication Daemon 1.0 in vmware-authd.exe in the VMware Authorization Service in VMware Workstation 7.0 befor...
CVE-2009-4810——The Secure Remote Password (SRP) implementation in Samhain before 2.5.4 does not check for a certain zero value where re...
CVE-2009-4809——Directory traversal vulnerability in thumbnail.ghp in Easy File Sharing (EFS) Web Server 4.8 allows remote attackers to ...
CVE-2009-4808——admin.php in Graugon PHP Article Publisher 1.0 allows remote attackers to bypass authentication and obtain administrativ...
CVE-2009-4807——Multiple SQL injection vulnerabilities in Graugon PHP Article Publisher 1.0 allow remote attackers to execute arbitrary ...
CVE-2009-4806——admin/save_user.asp in Digital Interchange Document Library 1.0.1 does not require administrative authentication, which ...
CVE-2009-4805——Multiple SQL injection vulnerabilities in EZ-Blog Beta 1, when magic_quotes_gpc is disabled, allow remote attackers to e...
CVE-2009-4804——Cross-site scripting (XSS) vulnerability in the Calendar Base (cal) extension before 1.1.1 for TYPO3, when Internet Expl...
CVE-2009-4803——SQL injection vulnerability in the Accessibility Glossary (a21glossary) extension 0.4.10 and earlier for TYPO3 allows re...
CVE-2009-4802——SQL injection vulnerability in the Flat Manager (flatmgr) extension before 1.9.16 for TYPO3 allows remote attackers to e...
CVE-2009-4801——EZ-Blog Beta 1 does not require authentication, which allows remote attackers to create or delete arbitrary posts via re...
CVE-2009-4800——Directory traversal vulnerability in Sysax Multi Server 4.3 and 4.5 allows remote authenticated users to delete arbitrar...
CVE-2009-4799——Diskos CMS 6.x stores sensitive information under the web root with insufficient access control, which allows remote att...
CVE-2009-4798——Multiple SQL injection vulnerabilities in Diskos CMS 6.x allow remote attackers to execute arbitrary SQL commands via th...
CVE-2009-4797——SQL injection vulnerability in browse.php in JobHut 1.2 and earlier allows remote attackers to execute arbitrary SQL com...
CVE-2009-4796——Multiple SQL injection vulnerabilities in the ExecuteQueries function in private/system/classes/listfactory.class.php in...
CVE-2009-4795——Multiple SQL injection vulnerabilities in Xlight FTP Server before 3.2.1, when ODBC authentication is enabled, allow rem...
CVE-2009-4794——Multiple SQL injection vulnerabilities in Community CMS 0.5 allow remote attackers to execute arbitrary SQL commands via...
CVE-2009-4793——Unrestricted file upload vulnerability in adminpanel/scripts/addphotos.php in BandSite CMS 1.1.4 allows remote authentic...
CVE-2009-4792——SQL injection vulnerability in includes/content/member_content.php in BandSite CMS 1.1.4 allows remote attackers to exec...
CVE-2009-4791——Multiple SQL injection vulnerabilities in Family Connections (aka FCMS) before 1.8.2 allow remote attackers to execute a...
CVE-2009-4790——Multiple directory traversal vulnerabilities in Sysax Multi Server 4.5 allow remote authenticated users to read or modif...
CVE-2009-4789——Multiple PHP remote file inclusion vulnerabilities in the MojoBlog component RC 0.15 for Joomla! allow remote attackers ...

Check if your code is affected by 2009 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now