NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
50653 | CVE-2009-3452 | WebCoreModule.ashx in RADactive I-Load before 2008.2.5.0 allows remote attackers to obtain sensitive information via unspecified requests that trigger responses containing the saved-image folder pathname. | 2 | 5 | Medium | 2017-01-07 | 2016-12-21 | View | |
51421 | CVE-2009-4298 | The LAMS module (mod/lams) for Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 stores the (1) username, (2) firstname, and (3) lastname fields within the user table, which allows attackers to obtain user account information via unknown vectors. | 2 | 5 | Medium | 2017-01-07 | 2009-12-16 | View | |
51933 | CVE-2009-4816 | Directory traversal vulnerability in api/download_checker.php in MegaLab The Uploader 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter. | 2 | 5 | Medium | 2017-01-07 | 2010-04-28 | View | |
52701 | CVE-2007-0477 | Cross-site scripting (XSS) vulnerability in Openads 2.0.x before 2.0.10, 2.3 before 2.3.31 (aka Max Media Manager before 0.3.31-alpha-pr2), and phpAdsNew/phpPgAds before 2.0.9-pr1 allows remote attackers to inject arbitrary web script or HTML via (1) the keyword parameter in admin-search.php and (2) affiliate-search.php. NOTE: this issue may overlap CVE-2007-0363. | 2 | 6.8 | Medium | 2017-01-07 | 2011-03-07 | View | |
53469 | CVE-2007-1266 | Evolution 2.8.1 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents Evolution from visually distinguishing between signed and unsigned portions of OpenPGP messages with multiple components, which allows remote attackers to forge the contents of a message without detection. | 2 | 5 | Medium | 2017-01-07 | 2011-03-07 | View |
Page 16459 of 17672, showing 5 records out of 88360 total, starting on record 82291, ending on 82295