NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
48119  CVE-2009-0802  Qbik WinGate, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint, which allows remote attackers to bypass access controls for Flash, Java, Silverlight, and probably other technologies, and possibly communicate with restricted intranet sites, via a crafted web page that causes a client to send HTTP requests with a modified Host header.    5.4  Medium  2017-01-07  2009-06-18  View
48375  CVE-2009-1065  SQL injection vulnerability in index.php in Pixie CMS 1.01a allows remote attackers to execute arbitrary SQL commands via the x parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.    7.5  High  2017-01-07  2009-03-26  View
48631  CVE-2009-1345  SQL injection vulnerability in document.php in cpCommerce 1.2.8 allows remote attackers to execute arbitrary SQL commands via the id_document parameter.    7.5  High  2017-01-07  2009-04-28  View
48887  CVE-2009-1618  Teraway LiveHelp 2.0 allows remote attackers to bypass authentication and gain administrative access via a pwd=&lvl=1&usr=&alias=admin&userid=1 value for the TWLHadmin cookie.    7.5  High  2017-01-07  2009-05-12  View
49143  CVE-2009-1878  Session fixation vulnerability in Adobe ColdFusion 8.0.1 and earlier allows remote attackers to hijack web sessions via unspecified vectors.    5.8  Medium  2017-01-07  2009-08-26  View

Page 14974 of 17672, showing 5 records out of 88360 total, starting on record 74866, ending on 74870

Actions