NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 49011 | CVE-2009-1742 | code.php in PC4Arb Pc4 Uploader 9.0 and earlier makes it easier for remote attackers to conduct SQL injection attacks via crafted keyword sequences that are removed from a filter in the id parameter in a banner action, as demonstrated via the "UNIunionON" string, which is collapsed into "UNION" by the filter_sql function. | 2 | 7.5 | High | 2017-01-07 | 2009-05-21 | View | |
| 5446 | CVE-2008-5704 | src/unit_test.c in gpsdrive (aka gpsdrive-scripts) 2.10~pre4 might allow local users to overwrite arbitrary files via a symlink attack on the /tmp/gpsdrive-unit-test/proc temporary file, a different vector than CVE-2008-4959 and CVE-2008-5380. | 2 | 7.6 | High | 2017-01-03 | 2009-05-20 | View | |
| 48999 | CVE-2009-1730 | Multiple directory traversal vulnerabilities in NetMechanica NetDecision TFTP Server 4.2 allow remote attackers to read or modify arbitrary files via directory traversal sequences in the (1) GET or (2) PUT command. | 2 | 10 | High | 2017-01-07 | 2009-05-20 | View | |
| 49000 | CVE-2009-1731 | SQL injection vulnerability in panel/index.php in MLFFAT 2.1 allows remote attackers to execute arbitrary SQL commands via a base64-encoded supervisor cookie. | 2 | 7.5 | High | 2017-01-07 | 2009-05-20 | View | |
| 6508 | CVE-2008-6777 | Multiple SQL injection vulnerabilities in MyPHP Forum 3.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in a confirm action, the (2) user parameter in a newconfirm action, and (3) reqpwd action to member.php; and the (4) quote parameter in a post action and (5) pid parameter in an edit action to post.php, different vectors than CVE-2005-0413.2 and CVE-2007-6667. | 2 | 5.1 | Medium | 2017-01-03 | 2009-05-20 | View |
Page 14587 of 17672, showing 5 records out of 88360 total, starting on record 72931, ending on 72935