NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 48246 | CVE-2009-0934 | Cross-site scripting (XSS) vulnerability in ejabberd before 2.0.4 allows remote attackers to inject arbitrary web script or HTML via unknown vectors related to links and MUC logs. | 2 | 4.3 | Medium | 2017-01-07 | 2009-06-08 | View | |
| 6543 | CVE-2008-6812 | SQL injection vulnerability in bukutamu.php in phpWebNews 0.2 MySQL Edition allows remote attackers to execute arbitrary SQL commands via the det parameter. | 2 | 7.5 | High | 2017-01-03 | 2009-06-08 | View | |
| 6556 | CVE-2008-6825 | Directory traversal vulnerability in user/index.php in Fonality trixbox CE 2.6.1 and earlier allows remote attackers to include and execute arbitrary files via a .. (dot dot) in the langChoice parameter. | 2 | 6.8 | Medium | 2017-01-03 | 2009-06-08 | View | |
| 49110 | CVE-2009-1844 | Multiple cross-site scripting (XSS) vulnerabilities in Drupal 5.x before 5.18 and 6.x before 6.12 allow (1) remote authenticated users to inject arbitrary web script or HTML via crafted UTF-8 byte sequences that are treated as UTF-7 by Internet Explorer 6 and 7, which are not properly handled in the "HTML exports of books" feature; and (2) allow remote authenticated users with administer taxonomy permissions to inject arbitrary web script or HTML via the help text of an arbitrary vocabulary. NOTE: vector 1 exists because of an incomplete fix for CVE-2009-1575. | 2 | 3.5 | Low | 2017-01-07 | 2009-06-08 | View | |
| 49114 | CVE-2009-1848 | SQL injection vulnerability in the JoomlaMe AgoraGroups (aka AG or com_agoragroup) component 0.3.5.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a groupdetail action to index.php. | 2 | 7.5 | High | 2017-01-07 | 2009-06-08 | View |
Page 14565 of 17672, showing 5 records out of 88360 total, starting on record 72821, ending on 72825