NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
47607 | CVE-2009-0273 | Multiple cross-site scripting (XSS) vulnerabilities in Novell GroupWise WebAccess 6.5x, 7.0, 7.01, 7.02x, 7.03, 7.03HP1a, and 8.0 allow remote attackers to inject arbitrary web script or HTML via the (1) User.id and (2) Library.queryText parameters to gw/webacc, and other vectors involving (3) HTML e-mail and (4) HTML attachments. | 2 | 4.3 | Medium | 2017-01-07 | 2009-02-05 | View | |
47863 | CVE-2009-0531 | SQL injection vulnerability in gallery/view.asp in A Better Member-Based ASP Photo Gallery before 1.2 allows remote attackers to execute arbitrary SQL commands via the entry parameter. | 2 | 7.5 | High | 2017-01-07 | 2009-03-10 | View | |
48119 | CVE-2009-0802 | Qbik WinGate, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint, which allows remote attackers to bypass access controls for Flash, Java, Silverlight, and probably other technologies, and possibly communicate with restricted intranet sites, via a crafted web page that causes a client to send HTTP requests with a modified Host header. | 2 | 5.4 | Medium | 2017-01-07 | 2009-06-18 | View | |
48375 | CVE-2009-1065 | SQL injection vulnerability in index.php in Pixie CMS 1.01a allows remote attackers to execute arbitrary SQL commands via the x parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | 2 | 7.5 | High | 2017-01-07 | 2009-03-26 | View | |
48631 | CVE-2009-1345 | SQL injection vulnerability in document.php in cpCommerce 1.2.8 allows remote attackers to execute arbitrary SQL commands via the id_document parameter. | 2 | 7.5 | High | 2017-01-07 | 2009-04-28 | View |
Page 17177 of 17672, showing 5 records out of 88360 total, starting on record 85881, ending on 85885