NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 49277 | CVE-2009-2015 | Directory traversal vulnerability in includes/file_includer.php in the Ideal MooFAQ (com_moofaq) component 1.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter. | 2 | 7.5 | High | 2017-01-07 | 2009-07-01 | View | |
| 49537 | CVE-2009-2289 | Cross-site scripting (XSS) vulnerability in index.php in Arcade Trade Script 1.0 beta allows remote attackers to inject arbitrary web script or HTML via the q parameter in a gamelist action. | 2 | 4.3 | Medium | 2017-01-07 | 2009-07-01 | View | |
| 49538 | CVE-2009-2290 | SQL injection vulnerability in the Boy Scout Advancement (com_bsadv) component 0.3 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a (1) account or (2) event task to index.php. | 2 | 7.5 | High | 2017-01-07 | 2009-07-01 | View | |
| 49539 | CVE-2009-2291 | Unspecified vulnerability in LoginToboggan 6.x-1.x before 6.x-1.5, a module for Drupal, when "Allow users to login using their e-mail address" is enabled, allows remote blocked users to bypass intended access restrictions via unspecified vectors. | 2 | 6.8 | Medium | 2017-01-07 | 2009-07-01 | View | |
| 49540 | CVE-2009-2292 | Cross-site scripting (XSS) vulnerability in Appleple a-News 2.32 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 2 | 4.3 | Medium | 2017-01-07 | 2009-07-01 | View |
Page 14489 of 17672, showing 5 records out of 88360 total, starting on record 72441, ending on 72445