| 48723 |
CVE-2009-1447 |
Unrestricted file upload vulnerability in admin/editor/image.php in e-cart.biz Free Shopping Cart allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in images/. |
|
2 |
6.8 |
Medium |
2017-01-07 |
2009-04-28 |
View
|
| 49235 |
CVE-2009-1973 |
Unspecified vulnerability in the Virtual Private Database component in Oracle Database 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote authenticated users to affect confidentiality and integrity, related to VPD policies. |
|
2 |
5.5 |
Medium |
2017-01-07 |
2012-10-22 |
View
|
| 49491 |
CVE-2009-2229 |
Directory traversal vulnerability in engine.php in Kasseler CMS 1.3.5 lite allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter during a download action, a different vector than CVE-2008-3087. NOTE: some of these details are obtained from third party information. |
|
2 |
5 |
Medium |
2017-01-07 |
2009-06-29 |
View
|
| 50003 |
CVE-2009-2778 |
Cross-site scripting (XSS) vulnerability in visitor/view.php in GarageSales Script allows remote attackers to inject arbitrary web script or HTML via the key parameter. NOTE: some of these details are obtained from third party information. |
|
2 |
4.3 |
Medium |
2017-01-07 |
2009-08-18 |
View
|
| 50259 |
CVE-2009-3044 |
Opera before 10.00 does not properly handle a (1) " |