NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
49635  CVE-2009-2388  SQL injection vulnerability in admin/index.php in Opial 1.0 allows remote attackers to execute arbitrary SQL commands via the txtPassword parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.    6.8  Medium  2017-01-07  2009-07-16  View
49636  CVE-2009-2389  Multiple SQL injection vulnerabilities in newsscript.php in USOLVED NEWSolved 1.1.6, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) jahr or (2) idneu parameter in an archive action, or (3) the newsid parameter.    6.8  Medium  2017-01-07  2009-07-16  View
49167  CVE-2009-1902  The multipart processor in ModSecurity before 2.5.9 allows remote attackers to cause a denial of service (crash) via a multipart form datapost request with a missing part header name, which triggers a NULL pointer dereference.    7.8  High  2017-01-07  2009-07-15  View
49168  CVE-2009-1903  The PDF XSS protection feature in ModSecurity before 2.5.8 allows remote attackers to cause a denial of service (Apache httpd crash) via a request for a PDF file that does not use the GET method.    4.3  Medium  2017-01-07  2009-07-15  View
5922  CVE-2008-6191  Conductor.exe in Intrinsic Swimage Encore before 5.0.1.21 contains a hardcoded password, which might allow local users to decrypt certain .bin files. NOTE: it is not clear whether this issue crosses privilege boundaries.    2.1  Low  2017-01-03  2009-07-15  View

Page 14451 of 17672, showing 5 records out of 88360 total, starting on record 72251, ending on 72255

Actions