NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
51965 | CVE-2009-4848 | Multiple cross-site scripting (XSS) vulnerabilities in ToutVirtual VirtualIQ Pro 3.2 build 7882 and 3.5 build 8691 allow remote attackers to inject arbitrary web script or HTML via the (1) userId parameter to tvserver/server/user/setPermissions.jsp, (2) deptName parameter to tvserver/server/user/addDepartment.jsp, (3) ID parameter to tvserver/server/inventory/inventoryTabs.jsp, (4) reportName parameter to tvserver/reports/virtualIQAdminReports.do, or (5) middleName parameter in a save action to tvserver/user/user.do. | 2 | 4.3 | Medium | 2017-01-07 | 2010-05-10 | View | |
52221 | CVE-2009-5125 | Comodo Internet Security before 3.9.95478.509 allows remote attackers to bypass malware detection in an RAR archive via an unspecified manipulation of the archive file format. | 2 | 4.3 | Medium | 2017-01-07 | 2012-08-27 | View | |
52477 | CVE-2007-0249 | Cross-site scripting (XSS) vulnerability in index.php in Nwom topsites 3.0 allows remote attackers to inject arbitrary web script or HTML via the o parameter. | 2 | 6.8 | Medium | 2017-01-07 | 2008-11-15 | View | |
52989 | CVE-2007-0769 | ** DISPUTED ** Cross-site scripting (XSS) vulnerability in register.php in Phorum 5.1.18 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: the vendor disputes this vulnerability, stating that "The characters are escaped properly." | 2 | 6.8 | Medium | 2017-01-07 | 2011-03-07 | View | |
53757 | CVE-2007-1573 | SQL injection vulnerability in admincp/attachment.php in Jelsoft vBulletin 3.6.5 allows remote authenticated administrators to execute arbitrary SQL commands via the "Attached Before" field. | 2 | 6 | Medium | 2017-01-07 | 2009-01-23 | View |
Page 17598 of 17672, showing 5 records out of 88360 total, starting on record 87986, ending on 87990