NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 47761 | CVE-2009-0429 | Multiple SQL injection vulnerabilities in Active Bids allow remote attackers to execute arbitrary SQL commands via the (1) search parameter to search.asp, (2) SortDir parameter to auctionsended.asp, and the (3) catid parameter to wishlist.php. | 2 | 7.5 | High | 2017-01-07 | 2009-02-05 | View | |
| 48017 | CVE-2009-0695 | hagent.exe in Wyse Device Manager (WDM) 4.7.x does not require authentication for commands, which allows remote attackers to obtain management access via a crafted query, as demonstrated by a V52 query that triggers a power-off action. | 2 | 7.5 | High | 2017-01-07 | 2012-06-26 | View | |
| 48273 | CVE-2009-0963 | Multiple SQL injection vulnerabilities in PHPRunner 4.2, and possibly earlier, allow remote attackers to execute arbitrary SQL commands via the SearchField parameter to (1) UserView_list.php, (2) orders_list.php, (3) users_list.php, and (4) Administrator_list.php. | 2 | 7.5 | High | 2017-01-07 | 2009-04-01 | View | |
| 51857 | CVE-2009-4740 | Directory traversal vulnerability in the Webesse E-Card (ws_ecard) extension 1.0.2 and earlier for TYPO3 has unspecified impact and remote attack vectors. | 2 | 7.5 | High | 2017-01-07 | 2010-03-29 | View | |
| 52881 | CVE-2007-0659 | download.php in the MuddyDogPaws FileDownload snippet before 2.5 for MODx allows remote attackers to download arbitrary files, as demonstrated by downloading config.inc.php to obtain database credentials. | 2 | 7.5 | High | 2017-01-07 | 2011-03-07 | View |
Page 14450 of 17672, showing 5 records out of 88360 total, starting on record 72246, ending on 72250