NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
48851  CVE-2009-1582  Million Dollar Text Links 1.0 does not properly restrict administrator access to admin.home.php, which allows remote attackers to bypass intended restrictions and gain privileges via a direct request to admin.home.php after visiting admin.php.    7.5  High  2017-01-07  2009-05-08  View
49107  CVE-2009-1841  js/src/xpconnect/src/xpcwrappedjsclass.cpp in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows remote attackers to execute arbitrary web script with the privileges of a chrome object, as demonstrated by the browser sidebar and the FeedWriter.    9.3  High  2017-01-07  2010-08-21  View
49363  CVE-2009-2101  Directory traversal vulnerability in archive.php in TorrentVolve 1.4, when register_globals is enabled, allows remote attackers to delete arbitrary files via a .. (dot dot) in the deleteTorrent parameter.    6.8  Medium  2017-01-07  2009-06-18  View
49619  CVE-2009-2372  Drupal 6.x before 6.13 does not prevent users from modifying user signatures after the associated comment format has been changed to an administrator-controlled input format, which allows remote authenticated users to inject arbitrary web script, HTML, and possibly PHP code via a crafted user signature.    6.5  Medium  2017-01-07  2009-07-08  View
49875  CVE-2009-2634  PHP remote file inclusion vulnerability in toolbar_ext.php in the MediaLibrary (com_media_library) component 1.5.3 Basic for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.    7.5  High  2017-01-07  2009-07-29  View

Page 14991 of 17672, showing 5 records out of 88360 total, starting on record 74951, ending on 74955

Actions