NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 48851 | CVE-2009-1582 | Million Dollar Text Links 1.0 does not properly restrict administrator access to admin.home.php, which allows remote attackers to bypass intended restrictions and gain privileges via a direct request to admin.home.php after visiting admin.php. | 2 | 7.5 | High | 2017-01-07 | 2009-05-08 | View | |
| 49107 | CVE-2009-1841 | js/src/xpconnect/src/xpcwrappedjsclass.cpp in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows remote attackers to execute arbitrary web script with the privileges of a chrome object, as demonstrated by the browser sidebar and the FeedWriter. | 2 | 9.3 | High | 2017-01-07 | 2010-08-21 | View | |
| 49363 | CVE-2009-2101 | Directory traversal vulnerability in archive.php in TorrentVolve 1.4, when register_globals is enabled, allows remote attackers to delete arbitrary files via a .. (dot dot) in the deleteTorrent parameter. | 2 | 6.8 | Medium | 2017-01-07 | 2009-06-18 | View | |
| 49619 | CVE-2009-2372 | Drupal 6.x before 6.13 does not prevent users from modifying user signatures after the associated comment format has been changed to an administrator-controlled input format, which allows remote authenticated users to inject arbitrary web script, HTML, and possibly PHP code via a crafted user signature. | 2 | 6.5 | Medium | 2017-01-07 | 2009-07-08 | View | |
| 49875 | CVE-2009-2634 | PHP remote file inclusion vulnerability in toolbar_ext.php in the MediaLibrary (com_media_library) component 1.5.3 Basic for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. | 2 | 7.5 | High | 2017-01-07 | 2009-07-29 | View |
Page 14991 of 17672, showing 5 records out of 88360 total, starting on record 74951, ending on 74955