NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
51686  CVE-2009-4569  SQL injection vulnerability in elkagroup Image Gallery allows remote attackers to execute arbitrary SQL commands via the id parameter to the default URI under news/.    7.5  High  2017-01-07  2010-01-06  View
51942  CVE-2009-4825  8pixel.net Blog 4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for App_Data/sb.mdb.    Medium  2017-01-07  2010-05-24  View
52198  CVE-2009-5097  Palm Pre WebOS 1.1 and earlier processes JavaScript in email messages, which allows remote attackers to execute arbitrary JavaScript, as demonstrated by reading PalmDatabase.db3.    7.1  High  2017-01-07  2011-09-14  View
52454  CVE-2007-0225  Cross-site scripting (XSS) vulnerability in shopcustadmin.asp in VP-ASP Shopping Cart 6.09 and earlier allows remote attackers to inject arbitrary web script or HTML via the msg parameter.    6.8  Medium  2017-01-07  2011-03-07  View
52710  CVE-2007-0486  ** DISPUTED ** Multiple PHP remote file inclusion vulnerabilities in Openads (aka phpAdsNew) 2.0.7 allow remote attackers to execute arbitrary PHP code via a URL in the (1) phpAds_geoPlugin parameter to libraries/lib-remotehost.inc, the (2) filename parameter to admin/report-index, or the (3) phpAds_config[my_footer] parameter to admin/lib-gui.inc. NOTE: the vendor has disputed this issue, stating that the relevant variables are used within function definitions.    7.5  High  2017-01-07  2008-11-13  View

Page 15962 of 17672, showing 5 records out of 88360 total, starting on record 79806, ending on 79810

Actions