Browse Database

Browsing Vulnerabilities Disclosed in January of 2009

<< Back to Browse
OSVDB IDDisclosure DateTitle
73465 2009-01-19 Monkey's Audio APE File Corruption Decoder Crash DoS
51499 2009-01-18 SCMS Simple Content Management System index.php p Parameter Traversal Local File Inclusion
53551 2009-01-18 Ralink Technology USB Wireless Adapter (RT73) Probe Request Packet SSID Handling Remote Overflow
51611 2009-01-18 WebSVN listing.php repname Parameter Remote File Access
51455 2009-01-18 Digital Sales IPN Database/Sales.mdb Direct Request Admin Credentials Disclosure
51473 2009-01-18 PHPads ads.dat Direct Request Admin Credentials Hash Disclosure
51470 2009-01-18 Ninja Blog entries/index.php cat Parameter Traversal Arbitrary File Access
51474 2009-01-18 PHPads admin.php ad_name Parameter XSS
51671 2009-01-18 Enhanced Simple PHP Gallery gallery/comment.php file Parameter Traversal Arbitrary File Access
57423 2009-01-17 Expat XML Parser Malformed UTF-8 Sequence Handling DoS
59737 2009-01-17 Expat libexpat lib/xmltok_impl.c updatePosition Function UTF-8 XML Document Handling Overflow DoS
57424 2009-01-17 Python expat Module (xml.parsers.expat) Malformed UTF-8 Sequence Handling DoS
51501 2009-01-17 Linux Kernel security/keys/keyctl.c keyctl_join_session_keyring Function Local DoS
55650 2009-01-16 Excel Viewer OCX ActiveX Unspecified Overflow DoS
51500 2009-01-16 ActionCalendar admin.asp pass Parameter SQL Injection
51562 2009-01-16 BibCiter reports/projects.php idp Parameter SQL Injection
51563 2009-01-16 BibCiter reports/contacts.php idc Parameter SQL Injection
51564 2009-01-16 BibCiter reports/users.php idu Parameter SQL Injection
51620 2009-01-16 eFAQ default.asp Multiple Parameter SQL Injection
51617 2009-01-16 Blog Manager inc_webblogmanager.asp ItemID Parameter SQL Injection
51618 2009-01-16 Blog Manager inc_webblogmanager.asp CategoryID Parameter XSS
51493 2009-01-16 AJ Classifieds Real Estate Image Upload Feature Unrestricted File Upload Arbitrary PHP Code Execution
51494 2009-01-16 AJ Classifieds Personals Image Upload Feature Unrestricted File Upload Arbitrary PHP Code Execution
51495 2009-01-16 AJ Classifieds Merchandise Image Upload Feature Unrestricted File Upload Arbitrary PHP Code Execution
52197 2009-01-16 Linux Kernel fs/notify/inotify/inotify_user.c inotify_read() List Mutex Unlocking DoS
51401 2009-01-16 Visuplay CMS news_article.php press_id Parameter SQL Injection
51456 2009-01-16 eReservations default.asp Multiple Parameter SQL Injection
51457 2009-01-16 BlogIt! index.asp Multiple Parameter SQL Injection
51453 2009-01-16 Ping IP login.aspx Multiple Parameter SQL Injection
51454 2009-01-16 MetaProducts MetaTreeX SaveToBMP.MetaTreeX ActiveX (MTXControl.OCX) Multiple Method Arbitrary File Overwrite
53509 2009-01-16 Sophos Anti-Virus Remote Management System (RMS) TAO GIOP Message Handling DoS
51458 2009-01-16 BlogIt! index.asp view Parameter XSS
51533 2009-01-16 RankEm rankup.asp siteID Parameter XSS
51534 2009-01-16 RankEm database/topsites.mdb Direct Request Credentials Disclosure
51640 2009-01-16 Walking Club login.aspx Multiple Parameter SQL Injection
51668 2009-01-16 Simple PHP Newsletter mail.php olang Parameter Traversal Arbitrary File Access
51669 2009-01-16 Simple PHP Newsletter mailbar.php olang Parameter Traversal Arbitrary File Access
51670 2009-01-16 BlogIt! database/Blog.mdb Direct Request Credentials Disclosure
51764 2009-01-16 Active Bids search.asp search Parameter XSS
51765 2009-01-16 Active Bids tellafriend.asp URL Parameter XSS

The database information may change without any notice. Use of the information constitutes acceptance for use in an AS IS condition, and there are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the copyright holder or distributor (OSVDB or OSF) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

© Copyright 2002 - 2013 Open Source Vulnerability Database (OSVDB), All Rights Reserved.
Privacy Statement - Terms of Use