49175 |
CVE-2009-1910 |
SQL injection vulnerability in index.php in RTWebalbum 1.0.462 allows remote attackers to execute arbitrary SQL commands via the AlbumId parameter. |
|
2 |
7.5 |
High |
2017-01-07 |
2009-06-05 |
View
|
49431 |
CVE-2009-2169 |
Insecure method vulnerability in the PDFVIEWER.PDFViewerCtrl.1 ActiveX control (pdfviewer.ocx) in Edraw PDF Viewer Component before 3.2.0.126 allows remote attackers to create and overwrite arbitrary files via a URL argument to the FtpConnect argument and a target filename argument to the FtpDownloadFile method. NOTE: this can be leveraged for code execution by writing to a Startup folder. |
|
2 |
9.3 |
High |
2017-01-07 |
2009-06-23 |
View
|
49687 |
CVE-2009-2442 |
Cross-site scripting (XSS) vulnerability in public/index.php in Linea21 1.2.1 allows remote attackers to inject arbitrary web script or HTML via the search parameter in a resultats-recherche action. |
|
2 |
4.3 |
Medium |
2017-01-07 |
2009-07-13 |
View
|
49943 |
CVE-2009-2702 |
KDE KSSL in kdelibs 3.5.4, 4.2.4, and 4.3 does not properly handle a " |