NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 49635 | CVE-2009-2388 | SQL injection vulnerability in admin/index.php in Opial 1.0 allows remote attackers to execute arbitrary SQL commands via the txtPassword parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | 2 | 6.8 | Medium | 2017-01-07 | 2009-07-16 | View | |
| 49636 | CVE-2009-2389 | Multiple SQL injection vulnerabilities in newsscript.php in USOLVED NEWSolved 1.1.6, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) jahr or (2) idneu parameter in an archive action, or (3) the newsid parameter. | 2 | 6.8 | Medium | 2017-01-07 | 2009-07-16 | View | |
| 49167 | CVE-2009-1902 | The multipart processor in ModSecurity before 2.5.9 allows remote attackers to cause a denial of service (crash) via a multipart form datapost request with a missing part header name, which triggers a NULL pointer dereference. | 2 | 7.8 | High | 2017-01-07 | 2009-07-15 | View | |
| 49168 | CVE-2009-1903 | The PDF XSS protection feature in ModSecurity before 2.5.8 allows remote attackers to cause a denial of service (Apache httpd crash) via a request for a PDF file that does not use the GET method. | 2 | 4.3 | Medium | 2017-01-07 | 2009-07-15 | View | |
| 5922 | CVE-2008-6191 | Conductor.exe in Intrinsic Swimage Encore before 5.0.1.21 contains a hardcoded password, which might allow local users to decrypt certain .bin files. NOTE: it is not clear whether this issue crosses privilege boundaries. | 2 | 2.1 | Low | 2017-01-03 | 2009-07-15 | View |
Page 14451 of 17672, showing 5 records out of 88360 total, starting on record 72251, ending on 72255