NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
49322  CVE-2009-2060  src/net/http/http_transaction_winhttp.cc in Google Chrome before 1.0.154.53 uses the HTTP Host header to determine the context of a document provided in a (1) 4xx or (2) 5xx CONNECT response from a proxy server, which allows man-in-the-middle attackers to execute arbitrary web script by modifying this CONNECT response, aka an "SSL tampering" attack.    5.8  Medium  2017-01-07  2009-06-23  View
49578  CVE-2009-2330  Cross-site scripting (XSS) vulnerability in admin/admin_menu.php in CMS Chainuk 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the menu parameter.    4.3  Medium  2017-01-07  2009-07-15  View
50858  CVE-2009-3660  PHP remote file inclusion vulnerability in libraries/database.php in Efront 3.5.4 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the path parameter. NOTE: this is only a vulnerability when the administrator does not follow recommendations in the product"s security documentation.    6.8  Medium  2017-01-07  2009-10-12  View
51882  CVE-2009-4765  CNR Hikaye Portal 2.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for db/hikaye.mdb.    Medium  2017-01-07  2010-04-14  View
52138  CVE-2009-5024  ViewVC before 1.1.11 allows remote attackers to bypass the cvsdb row_limit configuration setting, and consequently conduct resource-consumption attacks, via the limit parameter, as demonstrated by a "query revision history" request.    Medium  2017-01-07  2012-11-19  View

Page 14653 of 17672, showing 5 records out of 88360 total, starting on record 73261, ending on 73265

Actions