CVE List

Id CVE No. Status Description Phase Votes Comments Actions
39445  CVE-2009-2010  Candidate  Multiple SQL injection vulnerabilities in Haudenschilt Family Connections CMS (FCMS) 1.9 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) thread parameter to messageboard.php, (2) member parameter to profile.php, (3) pid parameter to gallery/index.php, and the (4) fcms_login_id cookie parameter.  Assigned (20090608)  None (candidate not yet proposed)    View
39701  CVE-2009-2266  Candidate  OXID eShop 4.x before 4.1.4-21266, 3.x, and 2.x allows remote attackers to obtain sensitive information (session details and order history of other users) via a crafted cookie.  Assigned (20090701)  None (candidate not yet proposed)    View
39957  CVE-2009-2522  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20090717)  None (candidate not yet proposed)    View
40213  CVE-2009-2778  Candidate  Cross-site scripting (XSS) vulnerability in visitor/view.php in GarageSales Script allows remote attackers to inject arbitrary web script or HTML via the key parameter. NOTE: some of these details are obtained from third party information.  Assigned (20090814)  None (candidate not yet proposed)    View
40469  CVE-2009-3034  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20090831)  None (candidate not yet proposed)    View

Page 1752 of 20943, showing 5 records out of 104715 total, starting on record 8756, ending on 8760

Actions