NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
47289  CVE-2012-6608  Cross-site scripting (XSS) vulnerability in xmlservices/E_book.php in Elastix 2.3.0 allows remote attackers to inject arbitrary web script or HTML via the Page parameter.    4.3  Medium  2017-01-19  2014-02-27  View
48313  CVE-2009-1003  Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, and 9.0 allows remote attackers to affect integrity via unknown vectors related to "access to source code of web pages."    Medium  2017-01-07  2012-10-22  View
48825  CVE-2009-1555  The Cisco Linksys WVC54GCA wireless video camera with firmware 1.00R22 and 1.00R24 sends configuration data in response to a Setup Wizard remote-management command, which allows remote attackers to obtain sensitive information such as passwords by reading the SetupWizard.exe process memory, a related issue to CVE-2008-4390.    Medium  2017-01-07  2009-05-23  View
49849  CVE-2009-2606  ASP Football Pool 2.3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for NFL.mdb.    Medium  2017-01-07  2009-07-27  View
50105  CVE-2009-2883  SQL injection vulnerability in admin/login.php in SaphpLesson 4.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the cp_username parameter, related to an error in the CleanVar function in includes/functions.php.    6.8  Medium  2017-01-07  2009-08-21  View

Page 15187 of 17672, showing 5 records out of 88360 total, starting on record 75931, ending on 75935

Actions