NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
48121 | CVE-2009-0804 | Ziproxy 2.6.0, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint, which allows remote attackers to bypass access controls for Flash, Java, Silverlight, and probably other technologies, and possibly communicate with restricted intranet sites, via a crafted web page that causes a client to send HTTP requests with a modified Host header. | 2 | 5.4 | Medium | 2017-01-07 | 2009-06-18 | View | |
48377 | CVE-2009-1067 | Cross-site scripting (XSS) vulnerability in index.php in Pixie CMS 1.01a allows remote attackers to inject arbitrary web script or HTML via the x parameter. | 2 | 4.3 | Medium | 2017-01-07 | 2009-03-26 | View | |
48633 | CVE-2009-1347 | Multiple SQL injection vulnerabilities in stats/index.php in chCounter 3.1.3 allow remote attackers to execute arbitrary SQL commands via (1) the login_name parameter (aka the username field) or (2) the login_pw parameter (aka the password field). | 2 | 6.8 | Medium | 2017-01-07 | 2009-04-20 | View | |
48889 | CVE-2009-1620 | Multiple cross-site scripting (XSS) vulnerabilities in input.php in MataChat allow remote attackers to inject arbitrary web script or HTML via the (1) nickname and (2) color parameters. | 2 | 4.3 | Medium | 2017-01-07 | 2009-05-12 | View | |
49145 | CVE-2009-1880 | Cross-site scripting (XSS) vulnerability in MT312 REP-BBS allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to (1) model.php and (2) config.php with timestamps before 20090521. | 2 | 4.3 | Medium | 2017-01-07 | 2009-06-02 | View |
Page 17253 of 17672, showing 5 records out of 88360 total, starting on record 86261, ending on 86265