NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
47761  CVE-2009-0429  Multiple SQL injection vulnerabilities in Active Bids allow remote attackers to execute arbitrary SQL commands via the (1) search parameter to search.asp, (2) SortDir parameter to auctionsended.asp, and the (3) catid parameter to wishlist.php.    7.5  High  2017-01-07  2009-02-05  View
48017  CVE-2009-0695  hagent.exe in Wyse Device Manager (WDM) 4.7.x does not require authentication for commands, which allows remote attackers to obtain management access via a crafted query, as demonstrated by a V52 query that triggers a power-off action.    7.5  High  2017-01-07  2012-06-26  View
48273  CVE-2009-0963  Multiple SQL injection vulnerabilities in PHPRunner 4.2, and possibly earlier, allow remote attackers to execute arbitrary SQL commands via the SearchField parameter to (1) UserView_list.php, (2) orders_list.php, (3) users_list.php, and (4) Administrator_list.php.    7.5  High  2017-01-07  2009-04-01  View
51857  CVE-2009-4740  Directory traversal vulnerability in the Webesse E-Card (ws_ecard) extension 1.0.2 and earlier for TYPO3 has unspecified impact and remote attack vectors.    7.5  High  2017-01-07  2010-03-29  View
52881  CVE-2007-0659  download.php in the MuddyDogPaws FileDownload snippet before 2.5 for MODx allows remote attackers to download arbitrary files, as demonstrated by downloading config.inc.php to obtain database credentials.    7.5  High  2017-01-07  2011-03-07  View

Page 14450 of 17672, showing 5 records out of 88360 total, starting on record 72246, ending on 72250

Actions