49632 |
CVE-2009-2385 |
SQL injection vulnerability in the awardsMembers function in Sources/Profile.php in the Member Awards component 1.0.2 for Simple Machines Forum (SMF) allows remote attackers to execute arbitrary SQL commands via the id parameter in a profile action to index.php. NOTE: some of these details are obtained from third party information. |
|
2 |
7.5 |
High |
2017-01-07 |
2009-07-09 |
View
|
49888 |
CVE-2009-2647 |
Unspecified vulnerability in Kaspersky Anti-Virus 2010 and Kaspersky Internet Security 2010 before Critical Fix 9.0.0.463 allows remote attackers to disable the Kaspersky application via unknown attack vectors unrelated to "an external script." |
|
2 |
5 |
Medium |
2017-01-07 |
2009-07-31 |
View
|
50144 |
CVE-2009-2923 |
Multiple directory traversal vulnerabilities in BitmixSoft PHP-Lance 1.52 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) language parameter to show.php and (2) in parameter to advanced_search.php. |
|
2 |
5 |
Medium |
2017-01-07 |
2009-08-26 |
View
|
50400 |
CVE-2009-3195 |
Multiple cross-site scripting (XSS) vulnerabilities in JCE-Tech Auction RSS Content Script 3.0 allow remote attackers to inject arbitrary web script or HTML via the id parameter to (1) rss.php and (2) search.php. |
|
2 |
4.3 |
Medium |
2017-01-07 |
2009-09-16 |
View
|
50656 |
CVE-2009-3455 |
Apple Safari, possibly before 4.0.3, on Mac OS X does not properly handle a " |