NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 48081 | CVE-2009-0762 | Cross-site scripting (XSS) vulnerability in ScriptsEz Ez PHP Comment allows remote attackers to inject arbitrary web script or HTML via the name parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | 2 | 4.3 | Medium | 2017-01-07 | 2009-03-06 | View | |
| 48085 | CVE-2009-0766 | Directory traversal vulnerability in default.php in Kipper 2.01 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the configfile parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | 2 | 7.5 | High | 2017-01-07 | 2009-03-06 | View | |
| 48086 | CVE-2009-0767 | Kipper 2.01 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a file containing credentials via a direct request for job/config.data. | 2 | 5 | Medium | 2017-01-07 | 2009-03-06 | View | |
| 48088 | CVE-2009-0769 | QIP 2005 build 8082 allows remote attackers to cause a denial of service (CPU consumption and application hang) via a crafted Rich Text Format (RTF) ICQ message, as demonstrated by an { tfpict&&} message. NOTE: the vulnerability may be in Sergey Tkachenko TRichView. If so, then this should not be treated as a vulnerability in QIP. | 2 | 4.3 | Medium | 2017-01-07 | 2009-03-06 | View | |
| 6130 | CVE-2008-6399 | Unspecified vulnerability in DotNetNuke 4.5.2 through 4.9 allows remote attackers to "add additional roles to their user account" via unknown attack vectors. | 2 | 6.4 | Medium | 2017-01-03 | 2009-03-06 | View |
Page 14841 of 17672, showing 5 records out of 88360 total, starting on record 74201, ending on 74205