CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
40169 | CVE-2009-2734 | Candidate | SQL injection vulnerability in the get_employee function in classweekreport.inc in Achievo before 1.4.0 allows remote attackers to execute arbitrary SQL commands via the userid parameter (aka user_id variable) to dispatch.php. | Assigned (20090810) | None (candidate not yet proposed) | View | |
40425 | CVE-2009-2990 | Candidate | Array index error in Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 might allow attackers to execute arbitrary code via unspecified vectors. | Assigned (20090827) | None (candidate not yet proposed) | View | |
40681 | CVE-2009-3246 | Candidate | SQL injection vulnerability in spnews.php in MyBuxScript PTC-BUX allows remote attackers to execute arbitrary SQL commands via the id parameter in an spnews action to the default URI. NOTE: some of these details are obtained from third party information. | Assigned (20090918) | None (candidate not yet proposed) | View | |
40937 | CVE-2009-3502 | Candidate | SQL injection vulnerability in music.php in BPowerHouse BPMusic 1.0 allows remote attackers to execute arbitrary SQL commands via the music_id parameter. | Assigned (20090930) | None (candidate not yet proposed) | View | |
41193 | CVE-2009-3758 | Candidate | SQL injection vulnerability in login.php in sample code in the XenServer Resource Kit in Citrix XenCenterWeb allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: some of these details are obtained from third party information. | Assigned (20091022) | None (candidate not yet proposed) | View |
Page 19173 of 20943, showing 5 records out of 104715 total, starting on record 95861, ending on 95865