NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 49371 | CVE-2009-2109 | Multiple directory traversal vulnerabilities in FretsWeb 1.2 allow remote attackers to read arbitrary files via directory traversal sequences in the (1) language parameter to charts.php and the (2) fretsweb_language cookie parameter to unspecified vectors, possibly related to admin/common.php. | 2 | 5 | Medium | 2017-01-07 | 2009-06-24 | View | |
| 49375 | CVE-2009-2113 | Multiple SQL injection vulnerabilities in FretsWeb 1.2 allow remote attackers to execute arbitrary SQL commands via the (1) name parameter to player.php and the (2) hash parameter to song.php. | 2 | 7.5 | High | 2017-01-07 | 2009-06-24 | View | |
| 49379 | CVE-2009-2117 | uye_paneli.php in phPortal 1.0 allows remote attackers to bypass authentication and obtain administrative access by setting the kulladi cookie to a valid username. | 2 | 7.5 | High | 2017-01-07 | 2009-06-24 | View | |
| 49380 | CVE-2009-2118 | Integer overflow in IrfanView 4.23, when the resampling or screen fitting option is enabled, allows remote attackers to execute arbitrary code via a crafted TIFF 1 BPP image, which triggers a heap-based buffer overflow. | 2 | 6.8 | Medium | 2017-01-07 | 2009-06-24 | View | |
| 49405 | CVE-2009-2143 | PHP remote file inclusion vulnerability in firestats-wordpress.php in the FireStats plugin before 1.6.2-stable for WordPress allows remote attackers to execute arbitrary PHP code via a URL in the fs_javascript parameter. | 2 | 7.5 | High | 2017-01-07 | 2009-06-24 | View |
Page 14510 of 17672, showing 5 records out of 88360 total, starting on record 72546, ending on 72550