NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 49372 | CVE-2009-2110 | Multiple directory traversal vulnerabilities in DB Top Sites 1.0, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the u parameter to (1) full.php, (2) index.php, and (3) contact.php. | 2 | 7.6 | High | 2017-01-07 | 2009-06-19 | View | |
| 49373 | CVE-2009-2111 | Static code injection vulnerability in add_reg.php in DB Top Sites 1.0 allows remote attackers to inject arbitrary PHP code via a crafted (1) url and (2) location parameter. | 2 | 10 | High | 2017-01-07 | 2009-06-19 | View | |
| 49376 | CVE-2009-2114 | Multiple cross-site scripting (XSS) vulnerabilities in admin.php in SkyBlueCanvas 1.1 r237 allow remote attackers to inject arbitrary web script or HTML via the (1) mgroup, (2) mgr, (3) objtype, (4) id, and (5) dir parameters. | 2 | 4.3 | Medium | 2017-01-07 | 2009-06-19 | View | |
| 49346 | CVE-2009-2084 | Simple Linux Utility for Resource Management (SLURM) 1.2 and 1.3 before 1.3.14 does not properly set supplementary groups before invoking (1) sbcast from the slurmd daemon or (2) strigger from the slurmctld daemon, which might allow local SLURM users to modify files and gain privileges. | 2 | 7.2 | High | 2017-01-07 | 2009-06-18 | View | |
| 49357 | CVE-2009-2095 | PHP remote file inclusion vulnerability in template/simpledefault/admin/_masterlayout.php in Mundi Mail 0.8.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the top parameter. NOTE: when allow_url_fopen is disabled, directory traversal attacks are possible to include and execute arbitrary local files. | 2 | 6.8 | Medium | 2017-01-07 | 2009-06-18 | View |
Page 14531 of 17672, showing 5 records out of 88360 total, starting on record 72651, ending on 72655