NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
48921 | CVE-2009-1652 | admin/adminaddeditdetails.php in Business Community Script does not properly restrict access, which allows remote attackers to gain privileges and add administrators via a direct request. | 2 | 7.5 | High | 2017-01-07 | 2009-05-23 | View | |
49177 | CVE-2009-1912 | Directory traversal vulnerability in src/func/language.php in webSPELL 4.2.0e and earlier allows remote attackers to include and execute arbitrary local .php files via a .. (dot dot) in a language cookie. NOTE: this can be leveraged for SQL injection by including awards.php. | 2 | 6.8 | Medium | 2017-01-07 | 2009-06-05 | View | |
49433 | CVE-2009-2171 | Mahara 1.1 before 1.1.5 does not apply permission checks when saving a view that contains artefacts, which allows remote authenticated users to read another user"s artefact. | 2 | 4 | Medium | 2017-01-07 | 2009-06-24 | View | |
49689 | CVE-2009-2444 | Directory traversal vulnerability in maillinglist/setup/step1.php.inc in ADbNewsSender before 1.5.6, and 2.0 before RC2, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the path_to_lang parameter to setup/index.php. | 2 | 7.5 | High | 2017-01-07 | 2009-07-14 | View | |
49945 | CVE-2009-2704 | CA SiteMinder allows remote attackers to bypass cross-site scripting (XSS) protections for J2EE applications via a request containing a %00 (encoded null byte). | 2 | 4.3 | Medium | 2017-01-07 | 2009-08-11 | View |
Page 1752 of 17672, showing 5 records out of 88360 total, starting on record 8756, ending on 8760