Browse Database

Browsing Vulnerabilities Disclosed in December of 2009

<< Back to Browse
OSVDB IDDisclosure DateTitle
64891 2009-12-31 Simple:Press Plugin for WordPress TinyBrowser Restriction Bypass Arbitrary File Upload
64893 2009-12-31 Simple:Press Plugin for WordPress Avatar Upload Handling Code Execution
61391 2009-12-31 Avatar Studio Module for PHP-Fusion avatar_studio.php Multiple Parameter Traversal Local File Inclusion
61393 2009-12-31 dB Masters Links Directory admin.php admin_log Cookie Manipulation Authentication Bypass
61402 2009-12-31 Run Digital Download Component for Joomla! File Access Unspecified Issue
61392 2009-12-31 FlashChat phpinfo.php Direct Request Information Disclosure
61394 2009-12-31 iDevAffiliate signup.php payable Parameter XSS
61398 2009-12-31 PicMe admin/banner.php URI XSS
61396 2009-12-31 UranyumSoft Listing Service database/db.mdb Direct Request Database Disclosure
61400 2009-12-31 Wing FTP Server Unspecified XSS
61401 2009-12-31 Wing FTP Server on Linux FTP Command Handling Remote DoS
61445 2009-12-31 Weatimages index.php path Parameter Traversal Arbitrary Directory Access
61449 2009-12-31 HLstatsX hlstats.php award Parameter SQL Injection
61453 2009-12-31 XOOPS modules/pm/readpmsg.php op Parameter XSS
61454 2009-12-31 News Module for XOOPS include/notification_update.php not_list Parameter SQL Injection
82826 2009-12-31 OpenConnect NetworkManager Authentication Dialog Use-after-free Remote DoS
61459 2009-12-30 PDF-XChange Viewer PDFXCview.exe PDF File Handling Memory Corruption
61388 2009-12-30 Esinti Web Design Gold Defter data/defter.mdb Direct Request Database Disclosure
61389 2009-12-30 phpAuction register.php Multiple Parameter XSS
61385 2009-12-30 Futility Forum message.mdb Direct Request Database Disclosure
61390 2009-12-30 Despe FreeCell solitaire.php Multiple Parameter XSS
61399 2009-12-30 Autocomplete Widgets for CCK Text and Number Module for Drupal Access Restriction Bypass
61397 2009-12-30 I-Escorts Directory country_escorts.php country_id Parameter SQL Injection
61561 2009-12-30 Artist avenue Component for Mambo / Joomla! index.php Itemid Parameter XSS
61563 2009-12-30 RoseOnlineCMS modules/admincp.php admin Parameter Traversal Local File Inclusion
61564 2009-12-30 Dictionary Module for XOOPS detail.php id Parameter SQL Injection
61386 2009-12-29 BigAnt Messenger AntServer Module (AntServer.exe) USV Request Handling Remote Overflow
61380 2009-12-29 SenseSites CommonSense CMS search.php q Parameter XSS
61424 2009-12-29 AproxEngine index.php Multiple Parameter SQL Injection
61384 2009-12-29 phpFK PHP Forum ohne search.php search Parameter XSS
61387 2009-12-29 MySimpleFileUploader upload.php File Upload Arbitrary PHP Code Execution
61381 2009-12-29 Helpdesk Pilot knowledgebase.php article_id Parameter SQL Injection
61395 2009-12-29 DirectAdmin Admin Account Creation CSRF
61419 2009-12-29 MyBB inc/functions_time.php Crafted Year Value Request Remote DoS
61425 2009-12-29 AproxEngine index.php Multiple Parameter XSS
61426 2009-12-29 AproxEngine engine/inc/galerie_unlink.php datei Parameter Arbitrary File Deletion
61427 2009-12-29 AproxEngine engine/inc/galerie_del_verz.php del_verz Parameter Arbitrary Directory Deletion
61428 2009-12-29 AproxEngine index.php from Parameter Admin Email Spoofing Weakness
61652 2009-12-29 Visualization Library Unspecified Issue
63881 2009-12-29 FreeWebshop.org HTTP Header IP Spoofing Weakness

The database information may change without any notice. Use of the information constitutes acceptance for use in an AS IS condition, and there are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the copyright holder or distributor (OSVDB or OSF) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

© Copyright 2002 - 2013 Open Source Vulnerability Database (OSVDB), All Rights Reserved.
Privacy Statement - Terms of Use