NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
48604  CVE-2009-1317  Multiple SQL injection vulnerabilities in Aqua CMS 1.1, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) userSID cookie parameter to droplets/functions/base.php and the (2) username parameter to admin/index.php.    6.8  Medium  2017-01-07  2009-04-17  View
48605  CVE-2009-1318  Directory traversal vulnerability in index.php in Jamroom 3.1.2, 3.2.3 through 3.2.6, 4.0.2, and possibly other versions before 3.4.0 allows remote attackers to include arbitrary files via directory traversal sequences in the t parameter.    6.5  Medium  2017-01-07  2009-04-17  View
48606  CVE-2009-1319  Directory traversal vulnerability in includes/ini.inc.php in GuestCal 2.1 allows remote attackers to include and execute arbitrary files via a .. (dot dot) in the lang parameter to index.php.    7.5  High  2017-01-07  2009-04-17  View
48607  CVE-2009-1320  Multiple cross-site scripting (XSS) vulnerabilities in include/zstore.php in Zazzle Store Builder 1.0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) gridPage and (2) gridSort parameters. NOTE: some of these details are obtained from third party information.    4.3  Medium  2017-01-07  2009-04-17  View
48608  CVE-2009-1321  Cross-site scripting (XSS) vulnerability in search.asp in ASP Product Catalog 1.0 allows remote attackers to inject arbitrary web script or HTML via the keywords parameter.    4.3  Medium  2017-01-07  2009-04-17  View

Page 14682 of 17672, showing 5 records out of 88360 total, starting on record 73406, ending on 73410

Actions