NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 49034 | CVE-2009-1765 | Multiple directory traversal vulnerabilities in pluck 4.6.2, when register_globals is enabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the langpref parameter to (1) data/modules/contactform/module_info.php, (2) data/modules/blog/module_info.php, and (3) data/modules/albums/module_info.php, different vectors than CVE-2008-3194. | 2 | 6.8 | Medium | 2017-01-07 | 2009-05-24 | View | |
| 49036 | CVE-2009-1767 | admin/edituser.php in 2daybiz Template Monster Clone does not require administrative authentication, which allows remote attackers to modify arbitrary accounts via the (1) loginname, (2) password, (3) email, (4) firstname, or (5) lastname parameter. | 2 | 5 | Medium | 2017-01-07 | 2009-05-24 | View | |
| 49041 | CVE-2009-1772 | Cross-site scripting (XSS) vulnerability in activeCollab 2.1 Corporate allows remote attackers to inject arbitrary web script or HTML via the re_route parameter to the login script. | 2 | 4.3 | Medium | 2017-01-07 | 2009-05-24 | View | |
| 49042 | CVE-2009-1773 | activeCollab 2.1 Corporate allows remote attackers to obtain sensitive information via an invalid re_route parameter to the login script, which reveals the installation path in an error message. | 2 | 5 | Medium | 2017-01-07 | 2009-05-24 | View | |
| 49048 | CVE-2009-1779 | PHP remote file inclusion vulnerability in admin.php in Frax.dk Php Recommend 1.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the form_include_template parameter. | 2 | 6.8 | Medium | 2017-01-07 | 2009-05-24 | View |
Page 14580 of 17672, showing 5 records out of 88360 total, starting on record 72896, ending on 72900