CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
40963 | CVE-2009-3528 | Candidate | SQL injection vulnerability in Profile.php in MyMsg 1.0.3 allows remote authenticated users to execute arbitrary SQL commands via the uid parameter in a show action. | Assigned (20091002) | None (candidate not yet proposed) | View | |
41219 | CVE-2009-3784 | Candidate | Open redirect vulnerability in Simplenews Statistics 6.x before 6.x-2.0, a module for Drupal, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. | Assigned (20091026) | None (candidate not yet proposed) | View | |
41475 | CVE-2009-4040 | Candidate | Cross-site scripting (XSS) vulnerability in phpMyFAQ before 2.0.17 and 2.5.x before 2.5.2, when used with Internet Explorer 6 or 7, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters to the search page. | Assigned (20091120) | None (candidate not yet proposed) | View | |
41731 | CVE-2009-4296 | Candidate | SQL injection vulnerability in the Taxonomy Timer module 5.x-1.8 and earlier and 6.x-alpha1 and earlier for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | Assigned (20091211) | None (candidate not yet proposed) | View | |
41987 | CVE-2009-4552 | Candidate | Cross-site scripting (XSS) vulnerability in the Survey Pro module for Miniweb 2.0 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php. | Assigned (20100104) | None (candidate not yet proposed) | View |
Page 305 of 20943, showing 5 records out of 104715 total, starting on record 1521, ending on 1525