NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 49407 | CVE-2009-2145 | Multiple cross-site scripting (XSS) vulnerabilities in transLucid 1.75 allow remote attackers to inject arbitrary web script or HTML via the (a) NodeID and (b) action parameters to the default URI, and the (c) NodeID parameter to the default URI for the admin section; and allow remote authenticated users to inject arbitrary web script or HTML via the (d) Title (aka page name) and (e) Url fields in a (1) new or (2) modified page. | 2 | 4.3 | Medium | 2017-01-07 | 2009-06-23 | View | |
| 49273 | CVE-2009-2011 | Worldweaver DX Studio Player 3.0.29.0, 3.0.22.0, 3.0.12.0, and probably other versions before 3.0.29.1, when used as a plug-in for Firefox, does not restrict access to the shell.execute JavaScript API method, which allows remote attackers to execute arbitrary commands via a .dxstudio file that invokes this method. | 2 | 9.3 | High | 2017-01-07 | 2009-06-22 | View | |
| 49377 | CVE-2009-2115 | admin.php in SkyBlueCanvas 1.1 r237 allows remote authenticated administrators to obtain sensitive information via an invalid id parameter, which reveals the installation path in an error message. | 2 | 6.8 | Medium | 2017-01-07 | 2009-06-22 | View | |
| 49378 | CVE-2009-2116 | Directory traversal vulnerability in admin.php in SkyBlueCanvas 1.1 r237 allows remote authenticated administrators to list directory contents via a .. (dot dot) in the dir parameter. | 2 | 4 | Medium | 2017-01-07 | 2009-06-22 | View | |
| 49384 | CVE-2009-2122 | SQL injection vulnerability in viewimg.php in the Paolo Palmonari Photoracer plugin 1.0 for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter. | 2 | 7.5 | High | 2017-01-07 | 2009-06-22 | View |
Page 14523 of 17672, showing 5 records out of 88360 total, starting on record 72611, ending on 72615