NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
47825  CVE-2009-0493  SQL injection vulnerability in login.php in IT!CMS 2.1a and earlier allows remote attackers to execute arbitrary SQL commands via the Username.    7.5  High  2017-01-07  2009-04-20  View
48337  CVE-2009-1027  SQL injection vulnerability in OpenCart 1.1.8 allows remote attackers to execute arbitrary SQL commands via the order parameter.    7.5  High  2017-01-07  2009-04-02  View
49361  CVE-2009-2099  SQL injection vulnerability in the iJoomla RSS Feeder (com_ijoomla_rss) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cat parameter in an xml action to index.php.    7.5  High  2017-01-07  2009-06-23  View
50385  CVE-2009-3180  Anantasoft Gazelle CMS 1.0 allows remote attackers to conduct a password reset for other users via a modified user parameter to renew.php.    7.5  High  2017-01-07  2009-09-14  View
52177  CVE-2009-5076  CRE Loaded before 6.2.14, and possibly other versions before 6.3.x, allows remote attackers to bypass authentication and gain administrator privileges via a request with (1) login.php or (2) password_forgotten.php appended as the PATH_INFO, which bypasses a check that uses PHP_SELF, which is not properly handled by (a) includes/application_top.php and (b) admin/includes/application_top.php, as exploited in the wild in 2009.    7.5  High  2017-01-07  2012-04-27  View

Page 15178 of 17672, showing 5 records out of 88360 total, starting on record 75886, ending on 75890

Actions