NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
49379 | CVE-2009-2117 | uye_paneli.php in phPortal 1.0 allows remote attackers to bypass authentication and obtain administrative access by setting the kulladi cookie to a valid username. | 2 | 7.5 | High | 2017-01-07 | 2009-06-24 | View | |
49635 | CVE-2009-2388 | SQL injection vulnerability in admin/index.php in Opial 1.0 allows remote attackers to execute arbitrary SQL commands via the txtPassword parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | 2 | 6.8 | Medium | 2017-01-07 | 2009-07-16 | View | |
49891 | CVE-2009-2650 | Heap-based buffer overflow in Sorcerer Software MultiMedia Jukebox 4.0 Build 020124 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted (1) .m3u or possibly (2) .pst file. | 2 | 9.3 | High | 2017-01-07 | 2009-08-27 | View | |
50147 | CVE-2009-2926 | Multiple SQL injection vulnerabilities in PHP Competition System BETA 0.84 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) day parameter to show_matchs.php and (2) pageno parameter to persons.php. | 2 | 7.5 | High | 2017-01-07 | 2009-08-21 | View | |
50403 | CVE-2009-3198 | Cross-site scripting (XSS) vulnerability in search.php in JCE-Tech Affiliate Master Datafeed Parser Script 2.0 allows remote attackers to inject arbitrary web script or HTML via the search parameter. | 2 | 4.3 | Medium | 2017-01-07 | 2009-09-16 | View |
Page 15966 of 17672, showing 5 records out of 88360 total, starting on record 79826, ending on 79830