NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 48363 | CVE-2009-1053 | chaozzDB 1.2 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing user credentials via a direct request for user.tsv. | 2 | 5 | Medium | 2017-01-07 | 2009-03-24 | View | |
| 48365 | CVE-2009-1055 | Unspecified vulnerability in the web service in Sitecore CMS 5.3.1 rev. 071114 allows remote authenticated users to gain access to security databases, and obtain administrative and user credentials, via unknown vectors related to SOAP and XML requests. | 2 | 4 | Medium | 2017-01-07 | 2009-03-24 | View | |
| 48140 | CVE-2009-0825 | SQL injection vulnerability in system/rss.php in TinX/cms 3.x before 3.5.1 allows remote attackers to execute arbitrary SQL commands via the id parameter. | 2 | 7.5 | High | 2017-01-07 | 2009-03-21 | View | |
| 48143 | CVE-2009-0828 | QuoteBook stores quotes.inc under the web root with insufficient access control, which allows remote attackers to obtain sensitive database information, including user credentials, via a direct request. | 2 | 5 | Medium | 2017-01-07 | 2009-03-21 | View | |
| 47376 | CVE-2009-0027 | The request handler in JBossWS in JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP06 and 4.3 before 4.3.0.CP04 does not properly validate the resource path during a request for a WSDL file with a custom web-service endpoint, which allows remote attackers to read arbitrary XML files via a crafted request. | 2 | 5 | Medium | 2017-01-07 | 2009-03-21 | View |
Page 14785 of 17672, showing 5 records out of 88360 total, starting on record 73921, ending on 73925