2009 CVE Vulnerabilities

5,054 CVEs published in 2009.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2009-3422——login.php in Zenas PaoLiber 1.1, when register_globals is enabled, allows remote attackers to bypass authentication and ...
CVE-2009-3420——Multiple cross-site scripting (XSS) vulnerabilities in index.php in the Publisher module 2.0 for Miniweb allow remote at...
CVE-2009-3419——SQL injection vulnerability in index.php in the Publisher module 2.0 for Miniweb allows remote attackers to execute arbi...
CVE-2009-3418——Multiple SQL injection vulnerabilities in Plume CMS 1.2.3 allow (1) remote authenticated users to execute arbitrary SQL ...
CVE-2009-3417——SQL injection vulnerability in the IDoBlog (com_idoblog) component 1.1 build 30 for Joomla! allows remote attackers to e...
CVE-2009-3390——Multiple unspecified vulnerabilities in the (1) iscsiadm and (2) iscsitadm programs in Sun Solaris 10, and OpenSolaris s...
CVE-2009-2817——Buffer overflow in Apple iTunes before 9.0.1 allows remote attackers to execute arbitrary code or cause a denial of serv...
CVE-2009-2682——Unspecified vulnerability in Role-Based Access Control (RBAC) in HP HP-UX B.11.23 and B.11.31 allows local users to bypa...
CVE-2009-3369——CgiUserConfigEdit in BackupPC 3.1.0, when SSH keys and Rsync are in use in a multi-user environment, does not restrict u...
CVE-2009-3368——Cross-site scripting (XSS) vulnerability in the Hotel Booking Reservation System (aka HBS or com_hbssearch) component fo...
CVE-2009-3367——Multiple cross-site scripting (XSS) vulnerabilities in An image gallery 1.0 allow remote attackers to inject arbitrary w...
CVE-2009-3366——Directory traversal vulnerability in navigation.php in An image gallery 1.0 allows remote attackers to list arbitrary di...
CVE-2009-3365——PHP remote file inclusion vulnerability in add-ons/modules/sysmanager/plugins/install.plugin.php in Aurora CMS 1.0.2 all...
CVE-2009-3364——Stack-based buffer overflow in FTPShell Client 4.1 RC2 allows remote FTP servers to execute arbitrary code via a long re...
CVE-2009-3363——Cross-site scripting (XSS) vulnerability in the BUEditor module 5.x before 5.x-1.2 and 6.x before 6.x-1.4, a module for ...
CVE-2009-3362——PHP remote file inclusion vulnerability in printnews.php3 in SZNews 2.7 allows remote attackers to execute arbitrary PHP...
CVE-2009-3361——SQL injection vulnerability in index.php in PHP-IPNMonitor allows remote attackers to execute arbitrary SQL commands via...
CVE-2009-3360——Multiple cross-site scripting (XSS) vulnerabilities in Datemill 1.0 allow remote attackers to inject arbitrary web scrip...
CVE-2009-3359——Multiple cross-site scripting (XSS) vulnerabilities in Match Agency BiZ 1.0 allow remote attackers to inject arbitrary w...
CVE-2009-3358——SQL injection vulnerability in profile.php in Tourism Scripts Adult Portal escort listing allows remote attackers to exe...
CVE-2009-3357——Multiple SQL injection vulnerabilities in the Hotel Booking Reservation System (aka HBS or com_hbssearch) component for ...
CVE-2009-3356——SQL injection vulnerability in index.php in Image voting 1.0 allows remote attackers to execute arbitrary SQL commands v...
CVE-2009-3355——Cross-site scripting (XSS) vulnerability in profile.php in Datetopia Buy Dating Site 1.0 allows remote attackers to inje...
CVE-2009-3354——Multiple unspecified vulnerabilities in the Rest API module for Drupal have unknown impact and attack vectors.
CVE-2009-3353——Multiple unspecified vulnerabilities in the Node2Node module for Drupal have unknown impact and attack vectors.

Check if your code is affected by 2009 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now