NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
47338 | CVE-2012-6691 | Multiple cross-site request forgery (CSRF) vulnerabilities in the admin panel in osCMax before 2.5.1 allow remote attackers to hijack the authentication of administrators for requests that conduct SQL injection attacks via the (1) status parameter to admin/stats_monthly_sales.php or (2) country parameter in a process action to admin/create_account_process.php. | 2 | 6.8 | Medium | 2017-01-19 | 2015-07-27 | View | |
47594 | CVE-2009-0260 | Multiple cross-site scripting (XSS) vulnerabilities in action/AttachFile.py in MoinMoin before 1.8.1 allow remote attackers to inject arbitrary web script or HTML via an AttachFile action to the WikiSandBox component with (1) the rename parameter or (2) the drawing parameter (aka the basename variable). | 2 | 4.3 | Medium | 2017-01-07 | 2016-12-07 | View | |
47850 | CVE-2009-0518 | VI Client in VMware VirtualCenter before 2.5 Update 4, VMware ESXi 3.5 before Update 4, and VMware ESX 3.5 before Update 4 retains the VirtualCenter Server password in process memory, which might allow local users to obtain this password. | 2 | 2.1 | Low | 2017-01-07 | 2010-08-21 | View | |
48106 | CVE-2009-0788 | Red Hat Network (RHN) Satellite Server 5.3 and 5.4 does not properly rewrite unspecified URLs, which allows remote attackers to (1) obtain unspecified sensitive host information or (2) use the server as an inadvertent proxy to connect to arbitrary services and IP addresses via unspecified vectors. | 2 | 6.4 | Medium | 2017-01-07 | 2011-04-19 | View | |
48362 | CVE-2009-1052 | FireAnt 1.3 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing user credentials via a direct request for user.tsv. | 2 | 5 | Medium | 2017-01-07 | 2009-04-02 | View |
Page 16389 of 17672, showing 5 records out of 88360 total, starting on record 81941, ending on 81945