NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
49078  CVE-2009-1812  Multiple SQL injection vulnerabilities in myGesuad 0.9.14 (aka 0.9) allow remote attackers to execute arbitrary SQL commands via (1) the formUser parameter (aka the Name field) to common/login.php, and allow remote authenticated users to execute arbitrary SQL commands via the ID parameter in a Detail action to (2) kategorie.php, (3) budget.php, (4) zahlung.php, or (5) adresse.php in modules/, related to classes/class.perform.php.    Medium  2017-01-07  2009-06-09  View
49087  CVE-2009-1821  DMXReady Registration Manager 1.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for databases/webblogmanager.mdb.    Medium  2017-01-07  2009-06-09  View
49091  CVE-2009-1825  modules/admuser.php in myColex 1.4.2 does not require administrative authentication, which allows remote authenticated users to list user accounts via a Find action.    Medium  2017-01-07  2009-06-09  View
49092  CVE-2009-1826  modules/admuser.php in myGesuad 0.9.14 (aka 0.9) does not require administrative authentication, which allows remote authenticated users to list user accounts via a Find action.    6.5  Medium  2017-01-07  2009-06-09  View
48072  CVE-2009-0753  Absolute path traversal vulnerability in MLDonkey 2.8.4 through 2.9.7 allows remote attackers to read arbitrary files via a leading "//" (double slash) in the filename.    Medium  2017-01-07  2009-06-09  View

Page 14560 of 17672, showing 5 records out of 88360 total, starting on record 72796, ending on 72800

Actions