NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
48607  CVE-2009-1320  Multiple cross-site scripting (XSS) vulnerabilities in include/zstore.php in Zazzle Store Builder 1.0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) gridPage and (2) gridSort parameters. NOTE: some of these details are obtained from third party information.    4.3  Medium  2017-01-07  2009-04-17  View
48863  CVE-2009-1594  Armorlogic Profense Web Application Firewall before 2.2.22, and 2.4.x before 2.4.4, does not properly implement the "positive model," which allows remote attackers to bypass certain protection mechanisms via a %0A (encoded newline), as demonstrated by a %0A in a cross-site scripting (XSS) attack URL.    7.5  High  2017-01-07  2010-08-30  View
49119  CVE-2009-1853  Multiple SQL injection vulnerabilities in index.php in Kensei Board 2.0 BETA (aka 2.0.0b) and earlier allow remote attackers to execute arbitrary SQL commands via the (1) f and (2) t parameters in a showforum action.    7.5  High  2017-01-07  2009-06-02  View
49375  CVE-2009-2113  Multiple SQL injection vulnerabilities in FretsWeb 1.2 allow remote attackers to execute arbitrary SQL commands via the (1) name parameter to player.php and the (2) hash parameter to song.php.    7.5  High  2017-01-07  2009-06-24  View
49631  CVE-2009-2384  Buffer overflow in amp.exe in Brothersoft PEamp 1.02b allows user-assisted remote attackers to execute arbitrary code via a long string in a .m3u playlist file. NOTE: some of these details are obtained from third party information.    9.3  High  2017-01-07  2009-07-09  View

Page 15133 of 17672, showing 5 records out of 88360 total, starting on record 75661, ending on 75665

Actions