CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
40966 | CVE-2009-3531 | Candidate | SQL injection vulnerability in vnews.php in Universe CMS 1.0.6 allows remote attackers to execute arbitrary SQL commands via the id parameter. | Assigned (20091002) | None (candidate not yet proposed) | View | |
41222 | CVE-2009-3787 | Candidate | files.php in Vivvo CMS 4.1.5.1 allows remote attackers to conduct directory traversal attacks and read arbitrary files via the file parameter with "logs/" in between two . (dot) characters, which is filtered into a "../" sequence. | Assigned (20091026) | None (candidate not yet proposed) | View | |
41478 | CVE-2009-4043 | Candidate | Cross-site scripting (XSS) vulnerability in the AddToAny module 5.x before 5.x-2.4 and 6.x before 6.x-2.4 for Drupal allows remote attackers to inject arbitrary web script or HTML via a node title. | Assigned (20091120) | None (candidate not yet proposed) | View | |
41734 | CVE-2009-4299 | Candidate | mod/glossary/showentry.php in the Glossary module for Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 does not properly perform access control, which allows attackers to read unauthorized Glossary entries via unknown vectors. | Assigned (20091211) | None (candidate not yet proposed) | View | |
41990 | CVE-2009-4555 | Candidate | Multiple cross-site request forgery (CSRF) vulnerabilities in AgoraCart 5.2.005 and 5.2.006 and AgoraCart GOLD 5.5.005 allow remote attackers to hijack the authentication of administrators for requests that (1) modify a .htaccess file via an unspecified request to protected/manager.cgi or (2) change the password of an administrative account. | Assigned (20100104) | None (candidate not yet proposed) | View |
Page 546 of 20943, showing 5 records out of 104715 total, starting on record 2726, ending on 2730