NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
49034  CVE-2009-1765  Multiple directory traversal vulnerabilities in pluck 4.6.2, when register_globals is enabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the langpref parameter to (1) data/modules/contactform/module_info.php, (2) data/modules/blog/module_info.php, and (3) data/modules/albums/module_info.php, different vectors than CVE-2008-3194.    6.8  Medium  2017-01-07  2009-05-24  View
49036  CVE-2009-1767  admin/edituser.php in 2daybiz Template Monster Clone does not require administrative authentication, which allows remote attackers to modify arbitrary accounts via the (1) loginname, (2) password, (3) email, (4) firstname, or (5) lastname parameter.    Medium  2017-01-07  2009-05-24  View
49041  CVE-2009-1772  Cross-site scripting (XSS) vulnerability in activeCollab 2.1 Corporate allows remote attackers to inject arbitrary web script or HTML via the re_route parameter to the login script.    4.3  Medium  2017-01-07  2009-05-24  View
49042  CVE-2009-1773  activeCollab 2.1 Corporate allows remote attackers to obtain sensitive information via an invalid re_route parameter to the login script, which reveals the installation path in an error message.    Medium  2017-01-07  2009-05-24  View
49048  CVE-2009-1779  PHP remote file inclusion vulnerability in admin.php in Frax.dk Php Recommend 1.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the form_include_template parameter.    6.8  Medium  2017-01-07  2009-05-24  View

Page 14580 of 17672, showing 5 records out of 88360 total, starting on record 72896, ending on 72900

Actions