NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
47865 | CVE-2009-0533 | Cross-site scripting (XSS) vulnerability in password.php in Scripts for Sites EZ Reminder allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly involving the u2 parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | 2 | 4.3 | Medium | 2017-01-07 | 2009-03-13 | View | |
48121 | CVE-2009-0804 | Ziproxy 2.6.0, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint, which allows remote attackers to bypass access controls for Flash, Java, Silverlight, and probably other technologies, and possibly communicate with restricted intranet sites, via a crafted web page that causes a client to send HTTP requests with a modified Host header. | 2 | 5.4 | Medium | 2017-01-07 | 2009-06-18 | View | |
48377 | CVE-2009-1067 | Cross-site scripting (XSS) vulnerability in index.php in Pixie CMS 1.01a allows remote attackers to inject arbitrary web script or HTML via the x parameter. | 2 | 4.3 | Medium | 2017-01-07 | 2009-03-26 | View | |
48633 | CVE-2009-1347 | Multiple SQL injection vulnerabilities in stats/index.php in chCounter 3.1.3 allow remote attackers to execute arbitrary SQL commands via (1) the login_name parameter (aka the username field) or (2) the login_pw parameter (aka the password field). | 2 | 6.8 | Medium | 2017-01-07 | 2009-04-20 | View | |
48889 | CVE-2009-1620 | Multiple cross-site scripting (XSS) vulnerabilities in input.php in MataChat allow remote attackers to inject arbitrary web script or HTML via the (1) nickname and (2) color parameters. | 2 | 4.3 | Medium | 2017-01-07 | 2009-05-12 | View |
Page 16902 of 17672, showing 5 records out of 88360 total, starting on record 84506, ending on 84510