NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 49049 | CVE-2009-1780 | admin.php in Frax.dk Php Recommend 1.3 and earlier does not require authentication when the user password is changed, which allows remote attackers to gain administrative privileges via modified form_admin_user and form_admin_pass parameters. | 2 | 7.5 | High | 2017-01-07 | 2009-05-27 | View | |
| 49561 | CVE-2009-2313 | Directory traversal vulnerability in index.php in Jinzora Media Jukebox 2.8 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the name parameter. | 2 | 7.5 | High | 2017-01-07 | 2009-07-02 | View | |
| 50329 | CVE-2009-3114 | The RSS reader widget in IBM Lotus Notes 8.0 and 8.5 saves items from an RSS feed as local HTML documents, which allows remote attackers to execute arbitrary script in Internet Explorer"s Local Machine Zone via a crafted feed, aka SPR RGAU7RDJ9K. | 2 | 7.5 | High | 2017-01-07 | 2009-10-01 | View | |
| 50585 | CVE-2009-3381 | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors. | 2 | 10 | High | 2017-01-07 | 2010-08-21 | View | |
| 51865 | CVE-2009-4748 | SQL injection vulnerability in mycategoryorder.php in the My Category Order plugin 2.8 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the parentID parameter in an act_OrderCategories action to wp-admin/post-new.php. | 2 | 7.5 | High | 2017-01-07 | 2010-03-29 | View |
Page 14524 of 17672, showing 5 records out of 88360 total, starting on record 72616, ending on 72620