NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
50714  CVE-2009-3513  Multiple cross-site scripting (XSS) vulnerabilities in Pilot Group (PG) eTraining allow remote attackers to inject arbitrary web script or HTML via (1) the cat_id parameter to courses_login.php, the id parameter to (2) news_read.php or (3) lessons_login.php, or (4) the cur parameter in a start action to lessons_login.php.    4.3  Medium  2017-01-07  2009-10-02  View
50970  CVE-2009-3802  Amiro.CMS 5.4.0.0 and earlier allows remote attackers to obtain sensitive information via an invalid loginname ("%%%") to _admin/index.php, which reveals the installation path and other information in an error message.    Medium  2017-01-07  2009-10-28  View
51226  CVE-2009-4076  Cross-site request forgery (CSRF) vulnerability in Roundcube Webmail 0.2.2 and earlier allows remote attackers to hijack the authentication of unspecified users for requests that modify user information via unspecified vectors, a different vulnerability than CVE-2009-4077.    6.8  Medium  2017-01-07  2015-08-24  View
51482  CVE-2009-4359  Cross-site scripting (XSS) vulnerability in folder.php in the SmartMedia 0.85 Beta module for XOOPS allows remote attackers to inject arbitrary web script or HTML via the categoryid parameter.    4.3  Medium  2017-01-07  2009-12-21  View
51738  CVE-2009-4621  SQL injection vulnerability in the JiangHu Inn plugin 1.1 and earlier for Discuz! allows remote attackers to execute arbitrary SQL commands via the id parameter in a show action to forummission.php.    7.5  High  2017-01-07  2011-04-28  View

Page 1610 of 17672, showing 5 records out of 88360 total, starting on record 8046, ending on 8050

Actions