NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
49446 | CVE-2009-2184 | Absolute path traversal vulnerability in forcedownload.php in Gravy Media Photo Host 1.0.8 allows remote attackers to read arbitrary files via an encoded "/" (slash) in the file parameter. | 2 | 5 | Medium | 2017-01-07 | 2009-08-07 | View | |
49702 | CVE-2009-2457 | The DSNDSD component in Novell eDirectory 8.8 before SP5 allows remote attackers to cause a denial of service (crash) via a malformed bind LDAP packet. | 2 | 5 | Medium | 2017-01-07 | 2009-07-16 | View | |
50470 | CVE-2009-3265 | Cross-site scripting (XSS) vulnerability in Opera 9 and 10 allows remote attackers to inject arbitrary web script or HTML via a (1) RSS or (2) Atom feed, related to the rendering of the application/rss+xml content type as "scripted content." NOTE: the vendor reportedly considers this behavior a "design feature," not a vulnerability. | 2 | 4.3 | Medium | 2017-01-07 | 2012-06-07 | View | |
50982 | CVE-2009-3814 | Static code injection vulnerability in RunCMS 2M1 allows remote authenticated administrators to execute arbitrary PHP code via the "Filter/Banning" feature, as demonstrated by modifying modules/system/cache/bademails.php using the "Prohibited: Emails" action, and other unspecified filters. | 2 | 6.5 | Medium | 2017-01-07 | 2009-10-28 | View | |
51238 | CVE-2009-4088 | Multiple directory traversal vulnerabilities in telepark.wiki 2.4.23 and earlier allow remote attackers to read arbitrary files via directory traversal sequences in the css parameter to (1) getjs.php and (2) getcsslocal.php; and include and execute arbitrary local files via the (3) group parameter to upload.php. | 2 | 6.8 | Medium | 2017-01-07 | 2010-03-31 | View |
Page 1410 of 17672, showing 5 records out of 88360 total, starting on record 7046, ending on 7050