NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
48922  CVE-2009-1653  Directory traversal vulnerability in examples/tbs_us_examples_0view.php in TinyButStrong 3.4.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the script parameter.    7.8  High  2017-01-07  2009-05-18  View
49178  CVE-2009-1913  SQL injection vulnerability in manager.php in LuxBum 0.5.5, when magic_quotes_gpc is disabled and dotclear authentication is used, allows remote attackers to execute arbitrary SQL commands via the username parameter in a login action.    5.1  Medium  2017-01-07  2009-06-05  View
49434  CVE-2009-2172  Cross-site scripting (XSS) vulnerability in forum/radioandtv.php in the Radio and TV Player addon for vBulletin allows remote registered users to inject arbitrary web script or HTML via the station parameter.    4.3  Medium  2017-01-07  2009-06-24  View
49690  CVE-2009-2445  Oracle iPlanet Web Server (formerly Sun Java System Web Server or Sun ONE Web Server) 6.1 before SP12, and 7.0 through Update 6, when running on Windows, allows remote attackers to read arbitrary JSP files via an alternate data stream syntax, as demonstrated by a .jsp::$DATA URI.    Medium  2017-01-07  2011-08-29  View
49946  CVE-2009-2705  CA SiteMinder allows remote attackers to bypass cross-site scripting (XSS) protections for J2EE applications via a request containing non-canonical, "overlong Unicode" in place of blacklisted characters.    4.3  Medium  2017-01-07  2009-08-11  View

Page 1820 of 17672, showing 5 records out of 88360 total, starting on record 9096, ending on 9100

Actions