NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
47585 | CVE-2009-0251 | Static code injection vulnerability in admin.php in Ryneezy phoSheezy 0.2 allows remote authenticated administrators to inject arbitrary PHP code into config/footer via the footer parameter. NOTE: this can be exploited by unauthenticated attackers by leveraging CVE-2009-0250. NOTE: some of these details are obtained from third party information. | 2 | 6.5 | Medium | 2017-01-07 | 2009-01-29 | View | |
48609 | CVE-2009-1322 | ASP Product Catalog 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing user credentials via a direct request for database/aspProductCatalog.mdb. | 2 | 5 | Medium | 2017-01-07 | 2009-04-17 | View | |
48865 | CVE-2009-1596 | Ignite Realtime Openfire before 3.6.5 does not properly implement the register.password (aka canChangePassword) console configuration setting, which allows remote authenticated users to bypass intended policy and change their own passwords via a passwd_change IQ packet. | 2 | 4 | Medium | 2017-01-07 | 2009-05-11 | View | |
49377 | CVE-2009-2115 | admin.php in SkyBlueCanvas 1.1 r237 allows remote authenticated administrators to obtain sensitive information via an invalid id parameter, which reveals the installation path in an error message. | 2 | 6.8 | Medium | 2017-01-07 | 2009-06-22 | View | |
49889 | CVE-2009-2648 | FlashDen Guestbook allows remote attackers to obtain configuration information via a direct request to amfphp/phpinfo.php, which calls the phpinfo function. | 2 | 5 | Medium | 2017-01-07 | 2009-07-31 | View |
Page 16599 of 17672, showing 5 records out of 88360 total, starting on record 82991, ending on 82995