NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
50714 | CVE-2009-3513 | Multiple cross-site scripting (XSS) vulnerabilities in Pilot Group (PG) eTraining allow remote attackers to inject arbitrary web script or HTML via (1) the cat_id parameter to courses_login.php, the id parameter to (2) news_read.php or (3) lessons_login.php, or (4) the cur parameter in a start action to lessons_login.php. | 2 | 4.3 | Medium | 2017-01-07 | 2009-10-02 | View | |
50970 | CVE-2009-3802 | Amiro.CMS 5.4.0.0 and earlier allows remote attackers to obtain sensitive information via an invalid loginname ("%%%") to _admin/index.php, which reveals the installation path and other information in an error message. | 2 | 5 | Medium | 2017-01-07 | 2009-10-28 | View | |
51226 | CVE-2009-4076 | Cross-site request forgery (CSRF) vulnerability in Roundcube Webmail 0.2.2 and earlier allows remote attackers to hijack the authentication of unspecified users for requests that modify user information via unspecified vectors, a different vulnerability than CVE-2009-4077. | 2 | 6.8 | Medium | 2017-01-07 | 2015-08-24 | View | |
51482 | CVE-2009-4359 | Cross-site scripting (XSS) vulnerability in folder.php in the SmartMedia 0.85 Beta module for XOOPS allows remote attackers to inject arbitrary web script or HTML via the categoryid parameter. | 2 | 4.3 | Medium | 2017-01-07 | 2009-12-21 | View | |
51738 | CVE-2009-4621 | SQL injection vulnerability in the JiangHu Inn plugin 1.1 and earlier for Discuz! allows remote attackers to execute arbitrary SQL commands via the id parameter in a show action to forummission.php. | 2 | 7.5 | High | 2017-01-07 | 2011-04-28 | View |
Page 1610 of 17672, showing 5 records out of 88360 total, starting on record 8046, ending on 8050