NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
48348  CVE-2009-1038  Multiple SQL injection vulnerabilities in YAP Blog 1.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) image_id parameter to comments.php, and remote authenticated administrators to execute arbitrary SQL commands via the (2) user parameter in a modif action to admin/index.php.    6.5  Medium  2017-01-07  2009-04-02  View
48604  CVE-2009-1317  Multiple SQL injection vulnerabilities in Aqua CMS 1.1, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) userSID cookie parameter to droplets/functions/base.php and the (2) username parameter to admin/index.php.    6.8  Medium  2017-01-07  2009-04-17  View
48860  CVE-2009-1591  CRLF injection vulnerability in CGI RESCUE Web Mailer before 1.04 allows remote attackers to inject arbitrary HTTP headers, and conduct cross-site scripting (XSS) or HTTP response splitting attacks, via CRLF sequences in an unspecified web form.    4.3  Medium  2017-01-07  2009-05-23  View
49628  CVE-2009-2381  Gizmo 3.1.0.79 on Linux does not verify a server"s SSL certificate, which allows remote servers to obtain the credentials of arbitrary users via a spoofed certificate.    Medium  2017-01-07  2009-07-09  View
50396  CVE-2009-3191  Multiple cross-site scripting (XSS) vulnerabilities in PAD Site Scripts 3.6 allow remote attackers to inject arbitrary web script or HTML via the cat parameter to (1) rss.php and (2) opml.php.    4.3  Medium  2017-01-07  2009-09-16  View

Page 16423 of 17672, showing 5 records out of 88360 total, starting on record 82111, ending on 82115

Actions