NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 49421 | CVE-2009-2159 | backup-database.php in TorrentTrader Classic 1.09 does not require administrative authentication, which allows remote attackers to create and download a backup database by making a direct request and then retrieving a .gz file from backups/. | 2 | 6.4 | Medium | 2017-01-07 | 2009-06-23 | View | |
| 49425 | CVE-2009-2163 | Cross-site scripting (XSS) vulnerability in login/default.aspx in Sitecore CMS before 6.0.2 Update-1 090507 allows remote attackers to inject arbitrary web script or HTML via the sc_error parameter. | 2 | 4.3 | Medium | 2017-01-07 | 2009-06-23 | View | |
| 49426 | CVE-2009-2164 | Multiple SQL injection vulnerabilities in Kjtechforce mailman beta1, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via (1) the code parameter to activate.php or (2) the dest parameter to index.php. | 2 | 6.8 | Medium | 2017-01-07 | 2009-06-23 | View | |
| 49428 | CVE-2009-2166 | Absolute path traversal vulnerability in cvs.php in OCS Inventory NG before 1.02.1 on Unix allows remote attackers to read arbitrary files via a full pathname in the log parameter. | 2 | 5 | Medium | 2017-01-07 | 2009-06-23 | View | |
| 49430 | CVE-2009-2168 | cpanel/login.php in EgyPlus 7ammel (aka 7ml) 1.0.1 and earlier sends a redirect to the web browser but does not exit when the supplied credentials are incorrect, which allows remote attackers to bypass authentication by providing arbitrary username and password parameters. | 2 | 7.5 | High | 2017-01-07 | 2009-06-23 | View |
Page 14513 of 17672, showing 5 records out of 88360 total, starting on record 72561, ending on 72565