CVE List

Id CVE No. Status Description Phase Votes Comments Actions
41480  CVE-2009-4045  Candidate  Multiple SQL injection vulnerabilities in FrontAccounting (FA) before 2.1.7 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to various .inc and .php files in (1) reporting/, (2) sales/, (3) sales/includes/, (4) sales/includes/db/, (5) sales/inquiry/, (6) sales/manage/, (7) sales/view/, (8) taxes/, and (9) taxes/db/.  Assigned (20091120)  None (candidate not yet proposed)    View
41736  CVE-2009-4301  Candidate  mnet/lib.php in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7, when MNET services are enabled, does not properly check permissions, which allows remote authenticated servers to execute arbitrary MNET functions.  Assigned (20091211)  None (candidate not yet proposed)    View
41992  CVE-2009-4557  Candidate  Cross-site scripting (XSS) vulnerability in the Image Assist module 5.x-1.x before 5.x-1.8, 5.x-2.x before 2.0-alpha4, 6.x-1.x before 6.x-1.1, 6.x-2.x before 2.0-alpha4, and 6.x-3.x-dev before 2009-07-15, a module for Drupal, allows remote authenticated users, with image-node creation privileges, to inject arbitrary web script or HTML via a node title.  Assigned (20100104)  None (candidate not yet proposed)    View
42248  CVE-2009-4813  Candidate  Cross-site scripting (XSS) vulnerability in myps.php in MyBB (aka MyBulletinBoard) 1.4.10 allows remote attackers to inject arbitrary web script or HTML via the username parameter in a donate action.  Assigned (20100427)  None (candidate not yet proposed)    View
42504  CVE-2009-5069  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20110405)  None (candidate not yet proposed)    View

Page 707 of 20943, showing 5 records out of 104715 total, starting on record 3531, ending on 3535

Actions