NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
3206  CVE-2008-3325  Cross-site request forgery (CSRF) vulnerability in Moodle 1.6.x before 1.6.7 and 1.7.x before 1.7.5 allows remote attackers to modify profile settings and gain privileges as other users via a link or IMG tag to the user edit profile page.    Medium  2017-01-03  2009-02-17  View
55706  CVE-2007-3555  Cross-site scripting (XSS) vulnerability in index.php in Moodle 1.7.1 allows remote attackers to inject arbitrary web script or HTML via a style expression in the search parameter, a different vulnerability than CVE-2004-1424.    4.3  Medium  2017-01-07  2009-02-17  View
47782  CVE-2009-0450  Stack-based buffer overflow in BlazeVideo HDTV Player 3.5 and earlier allows remote attackers to execute arbitrary code via a long string in a playlist (aka .plf) file.    9.3  High  2017-01-07  2009-02-17  View
3786  CVE-2008-3924  The "Make a backup" functionality in Content Management Made Easy (CMME) 1.12 stores sensitive information under the web root with insufficient access control, which allows remote attackers to discover (1) account names and (2) password hashes via a direct request for (a) backup/cmme_data.zip or (b) backup/cmme_cmme.zip. NOTE: it was later reported that vector a also affects CMME 1.19.    4.3  Medium  2017-01-03  2009-02-17  View
47819  CVE-2009-0487  Cross-site scripting (XSS) vulnerability in Mahara before 1.0.9 allows remote attackers to inject arbitrary web script or HTML via a crafted forum post.    4.3  Medium  2017-01-07  2009-02-17  View

Page 14911 of 17672, showing 5 records out of 88360 total, starting on record 74551, ending on 74555

Actions