NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 49498 | CVE-2009-2236 | SQL injection vulnerability in yad-admin/login.php in Your Article Directory allows remote attackers to execute arbitrary SQL commands via the txtAdminEmail parameter. NOTE: some of these details are obtained from third party information. | 2 | 7.5 | High | 2017-01-07 | 2009-06-29 | View | |
| 49499 | CVE-2009-2237 | Unspecified vulnerability in Views Bulk Operations 5.x-1.x before 5.x-1.4 and 6.x-1.x before 6.x-1.7, a module for Drupal, allows remote attackers to bypass intended access restrictions and modify "nodes or classes of nodes" via unknown vectors, probably related to registered procedures (aka actions). | 2 | 7.5 | High | 2017-01-07 | 2009-06-29 | View | |
| 49500 | CVE-2009-2238 | Unrestricted file upload vulnerability in includes/shared_scripts/wysiwyg_editor/assetmanager/assetmanager.asp in DMXReady Registration Manager 1.1 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in assets/webblogmanager. | 2 | 6.8 | Medium | 2017-01-07 | 2009-06-29 | View | |
| 49503 | CVE-2009-2241 | Cross-site scripting (XSS) vulnerability in search.asp in ASP Inline Corporate Calendar allows remote attackers to inject arbitrary web script or HTML via the keyword parameter. | 2 | 4.3 | Medium | 2017-01-07 | 2009-06-29 | View | |
| 49504 | CVE-2009-2242 | SQL injection vulnerability in active_appointments.asp in ASP Inline Corporate Calendar allows remote attackers to execute arbitrary SQL commands via the order parameter. | 2 | 6.8 | Medium | 2017-01-07 | 2009-06-29 | View |
Page 14499 of 17672, showing 5 records out of 88360 total, starting on record 72491, ending on 72495