NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
49385 | CVE-2009-2123 | Multiple SQL injection vulnerabilities in Elvin 1.2.0 allow remote attackers to execute arbitrary SQL commands via the (1) inUser (aka Username) and (2) inPass (aka Password) parameters to (a) inc/login.ei, reachable through login.php; and the (3) id parameter to (b) show_bug.php and (c) show_activity.php. NOTE: it was later reported that vector 3c also affects 1.2.2. | 2 | 7.5 | High | 2017-01-07 | 2009-08-24 | View | |
49641 | CVE-2009-2394 | SQL injection vulnerability in cat.php in SMSPages 1.0 in Mr.Saphp Arabic Script Mobile (aka Messages Library) 2.0 allows remote attackers to execute arbitrary SQL commands via the CatID parameter. | 2 | 7.5 | High | 2017-01-07 | 2009-07-09 | View | |
49897 | CVE-2009-2656 | Unspecified vulnerability in the com.android.phone process in Android 1.0, 1.1, and 1.5 allows remote attackers to cause a denial of service (network disconnection) via a crafted SMS message, as demonstrated by Collin Mulliner and Charlie Miller at Black Hat USA 2009. | 2 | 5 | Medium | 2017-01-07 | 2012-02-29 | View | |
50153 | CVE-2009-2932 | Cross-site scripting (XSS) vulnerability in uddiclient/process in the UDDI client in SAP NetWeaver Application Server (Java) 7.0 allows remote attackers to inject arbitrary web script or HTML via the TModel Key field. | 2 | 4.3 | Medium | 2017-01-07 | 2009-08-24 | View | |
50409 | CVE-2009-3204 | Multiple cross-site scripting (XSS) vulnerabilities in Stiva Forum 1.0 allow remote attackers to inject arbitrary web script or HTML via the id parameter to (1) demo.php and (2) forum.php, and the PATH_INFO to (3) include_forum.php. | 2 | 4.3 | Medium | 2017-01-07 | 2009-09-17 | View |
Page 15814 of 17672, showing 5 records out of 88360 total, starting on record 79066, ending on 79070