NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
49589  CVE-2009-2341  SQL injection vulnerability in albumdetail.php in Opial 1.0 allows remote attackers to execute arbitrary SQL commands via the albumid parameter.    7.5  High  2017-01-07  2009-07-09  View
49591  CVE-2009-2343  Cross-site scripting (XSS) vulnerability in people.php in Zoph before 0.7.0.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: some of these details are obtained from third party information.    4.3  Medium  2017-01-07  2009-07-09  View
49603  CVE-2009-2356  Multiple stack-based buffer overflows in the pgsqlQuery function in NullLogic Groupware 1.2.7, when PostgreSQL is used, might allow remote attackers to execute arbitrary code via input to the (1) POP3, (2) SMTP, or (3) web component that triggers a long SQL query.    9.3  High  2017-01-07  2009-07-09  View
49604  CVE-2009-2357  The default configuration of TekRADIUS 3.0 uses the sa account to communicate with Microsoft SQL Server, which makes it easier for remote attackers to obtain privileged access to the database and the underlying Windows operating system.    10  High  2017-01-07  2009-07-09  View
49626  CVE-2009-2379  Directory traversal vulnerability in public/index.php in BIGACE Web CMS 2.6 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the cmd parameter.    6.8  Medium  2017-01-07  2009-07-09  View

Page 14467 of 17672, showing 5 records out of 88360 total, starting on record 72331, ending on 72335

Actions