NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 48604 | CVE-2009-1317 | Multiple SQL injection vulnerabilities in Aqua CMS 1.1, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) userSID cookie parameter to droplets/functions/base.php and the (2) username parameter to admin/index.php. | 2 | 6.8 | Medium | 2017-01-07 | 2009-04-17 | View | |
| 48605 | CVE-2009-1318 | Directory traversal vulnerability in index.php in Jamroom 3.1.2, 3.2.3 through 3.2.6, 4.0.2, and possibly other versions before 3.4.0 allows remote attackers to include arbitrary files via directory traversal sequences in the t parameter. | 2 | 6.5 | Medium | 2017-01-07 | 2009-04-17 | View | |
| 48606 | CVE-2009-1319 | Directory traversal vulnerability in includes/ini.inc.php in GuestCal 2.1 allows remote attackers to include and execute arbitrary files via a .. (dot dot) in the lang parameter to index.php. | 2 | 7.5 | High | 2017-01-07 | 2009-04-17 | View | |
| 48607 | CVE-2009-1320 | Multiple cross-site scripting (XSS) vulnerabilities in include/zstore.php in Zazzle Store Builder 1.0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) gridPage and (2) gridSort parameters. NOTE: some of these details are obtained from third party information. | 2 | 4.3 | Medium | 2017-01-07 | 2009-04-17 | View | |
| 48608 | CVE-2009-1321 | Cross-site scripting (XSS) vulnerability in search.asp in ASP Product Catalog 1.0 allows remote attackers to inject arbitrary web script or HTML via the keywords parameter. | 2 | 4.3 | Medium | 2017-01-07 | 2009-04-17 | View |
Page 14682 of 17672, showing 5 records out of 88360 total, starting on record 73406, ending on 73410