NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
50222 | CVE-2009-3005 | Lunascape 5.1.3 and 5.1.4 allows remote attackers to spoof the address bar, via window.open with a relative URI, to show an arbitrary URL on the web site visited by the victim, as demonstrated by a visit to an attacker-controlled web page, which triggers a spoofed login form for the site containing that page. NOTE: a related attack was reported in which an arbitrary file: URL is shown. | 2 | 4.3 | Medium | 2017-01-07 | 2009-09-05 | View | |
50734 | CVE-2009-3534 | Directory traversal vulnerability in index.php in LionWiki 3.0.3, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter. | 2 | 6.8 | Medium | 2017-01-07 | 2009-10-05 | View | |
51502 | CVE-2009-4379 | Multiple cross-site scripting (XSS) vulnerabilities in Valarsoft Webmatic before 3.0.3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different issue than CVE-2008-2924. | 2 | 4.3 | Medium | 2017-01-07 | 2009-12-23 | View | |
52526 | CVE-2007-0298 | PHP remote file inclusion vulnerability in show.php in LunarPoll, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the PollDir parameter. | 2 | 6.8 | Medium | 2017-07-18 | 2017-07-11 | View | |
53038 | CVE-2007-0821 | Multiple directory traversal vulnerabilities in Cedric CLAIRE PortailPhp 2 allow remote attackers to read arbitrary files via a .. (dot dot) in the chemin parameter to (1) mod_news/index.php or (2) mod_news/goodies.php. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information. | 2 | 5 | Medium | 2017-01-07 | 2008-11-15 | View |
Page 1688 of 17672, showing 5 records out of 88360 total, starting on record 8436, ending on 8440