NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
48921  CVE-2009-1652  admin/adminaddeditdetails.php in Business Community Script does not properly restrict access, which allows remote attackers to gain privileges and add administrators via a direct request.    7.5  High  2017-01-07  2009-05-23  View
49177  CVE-2009-1912  Directory traversal vulnerability in src/func/language.php in webSPELL 4.2.0e and earlier allows remote attackers to include and execute arbitrary local .php files via a .. (dot dot) in a language cookie. NOTE: this can be leveraged for SQL injection by including awards.php.    6.8  Medium  2017-01-07  2009-06-05  View
49433  CVE-2009-2171  Mahara 1.1 before 1.1.5 does not apply permission checks when saving a view that contains artefacts, which allows remote authenticated users to read another user"s artefact.    Medium  2017-01-07  2009-06-24  View
49689  CVE-2009-2444  Directory traversal vulnerability in maillinglist/setup/step1.php.inc in ADbNewsSender before 1.5.6, and 2.0 before RC2, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the path_to_lang parameter to setup/index.php.    7.5  High  2017-01-07  2009-07-14  View
49945  CVE-2009-2704  CA SiteMinder allows remote attackers to bypass cross-site scripting (XSS) protections for J2EE applications via a request containing a %00 (encoded null byte).    4.3  Medium  2017-01-07  2009-08-11  View

Page 1752 of 17672, showing 5 records out of 88360 total, starting on record 8756, ending on 8760

Actions