| 49633 |
CVE-2009-2386 |
Insecure method vulnerability in Awingsoft Awakening Winds3D Viewer plugin 3.5.0.0, 3.0.0.5, and possibly other versions allows remote attackers to force the download and execution of arbitrary files via the GetURL method. |
|
2 |
9.3 |
High |
2017-01-07 |
2009-07-13 |
View
|
| 49889 |
CVE-2009-2648 |
FlashDen Guestbook allows remote attackers to obtain configuration information via a direct request to amfphp/phpinfo.php, which calls the phpinfo function. |
|
2 |
5 |
Medium |
2017-01-07 |
2009-07-31 |
View
|
| 50145 |
CVE-2009-2924 |
Multiple SQL injection vulnerabilities in Videos Broadcast Yourself 2 allow remote attackers to execute arbitrary SQL commands via the (1) UploadID parameter to videoint.php, and possibly the (2) cat_id parameter to catvideo.php and (3) uid parameter to cviewchannels.php. |
|
2 |
7.5 |
High |
2017-01-07 |
2009-08-21 |
View
|
| 50401 |
CVE-2009-3196 |
Cross-site scripting (XSS) vulnerability in index.php in JCE-Tech PHP Video Script allows remote attackers to inject arbitrary web script or HTML via the key parameter. |
|
2 |
4.3 |
Medium |
2017-01-07 |
2009-09-16 |
View
|
| 50657 |
CVE-2009-3456 |
Google Chrome, possibly 3.0.195.21 and earlier, does not properly handle a " |