NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
49386  CVE-2009-2124  Directory traversal vulnerability in page.php in Elvin 1.2.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the id parameter.    7.5  High  2017-01-07  2009-06-22  View
49388  CVE-2009-2126  Cross-site scripting (XSS) vulnerability in close_bug.php in Elvin before 1.2.1 allows remote attackers to inject arbitrary web script or HTML via the title (aka subject) field.    4.3  Medium  2017-01-07  2009-06-22  View
49389  CVE-2009-2127  Cross-site scripting (XSS) vulnerability in show_activity.php in Elvin 1.2.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter.    4.3  Medium  2017-01-07  2009-06-22  View
49390  CVE-2009-2128  SQL injection vulnerability in close_bug.php in Elvin before 1.2.1 allows remote attackers to execute arbitrary SQL commands via the title (aka subject) field.    7.5  High  2017-01-07  2009-06-22  View
49391  CVE-2009-2129  Cross-site request forgery (CSRF) vulnerability in login.php in Elvin 1.2.0 allows remote attackers to hijack the authentication of arbitrary users via a logout action.    6.8  Medium  2017-01-07  2009-06-22  View

Page 14524 of 17672, showing 5 records out of 88360 total, starting on record 72616, ending on 72620

Actions