NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
49409  CVE-2009-2147  SQL injection vulnerability in fdown.php in phpWebThings 1.5.2 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.    7.5  High  2017-01-07  2009-06-23  View
49410  CVE-2009-2148  SQL injection vulnerability in news/index.php in Campus Virtual-LMS allows remote attackers to execute arbitrary SQL commands via the id parameter.    7.5  High  2017-01-07  2009-06-23  View
49411  CVE-2009-2149  Multiple cross-site scripting (XSS) vulnerabilities in Campus Virtual-LMS allow remote attackers to inject arbitrary web script or HTML via the (1) courseid parameter to enrolments/step1.php, or the (2) search or (3) siteid parameter to files/shared_list.php.    4.3  Medium  2017-01-07  2009-06-23  View
49412  CVE-2009-2150  Multiple cross-site request forgery (CSRF) vulnerabilities in Campus Virtual-LMS allow (1) remote attackers to hijack the authentication of arbitrary users for requests that terminate a session via login/logout.php, and might allow remote attackers to hijack the authentication of certain users via a (2) ADD or (3) DELETE action to enrolments/step2.php.    6.8  Medium  2017-01-07  2009-06-23  View
49413  CVE-2009-2151  Directory traversal vulnerability in index.php in AdaptWeb 0.9.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the newlang parameter.    Medium  2017-01-07  2009-06-23  View

Page 14511 of 17672, showing 5 records out of 88360 total, starting on record 72551, ending on 72555

Actions