NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 49586 | CVE-2009-2338 | Directory traversal vulnerability in includes/startmodules.inc.php in FreeWebshop.org 2.2.9 R2, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang_file parameter. | 2 | 6.8 | Medium | 2017-01-07 | 2009-07-22 | View | |
| 48057 | CVE-2009-0738 | SQL injection vulnerability in login.php in Auth Php 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) passwd parameters. | 2 | 7.5 | High | 2017-01-07 | 2009-07-22 | View | |
| 48059 | CVE-2009-0740 | SQL injection vulnerability in login.php in BlueBird Prelease allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) passwd parameters. | 2 | 7.5 | High | 2017-01-07 | 2009-07-22 | View | |
| 49608 | CVE-2009-2361 | SQL injection vulnerability in include/class.staff.php in osTicket before 1.6 RC5 allows remote attackers to execute arbitrary SQL commands via the staff username parameter. | 2 | 7.5 | High | 2017-01-07 | 2009-07-22 | View | |
| 6090 | CVE-2008-6359 | Cross-site scripting (XSS) vulnerability in index.php in Max"s Guestbook allows remote attackers to inject arbitrary web script or HTML via the (1) name, (2) email, and (3) message parameters. | 2 | 4.3 | Medium | 2017-01-03 | 2009-07-22 | View |
Page 14438 of 17672, showing 5 records out of 88360 total, starting on record 72186, ending on 72190