NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 40249 | CVE-2013-4701 | Auth/Yadis/XML.php in PHP OpenID Library 2.2.2 and earlier allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via XRDS data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. | 2 | 7.5 | High | 2017-01-18 | 2016-11-28 | View | |
| 46137 | CVE-2012-4869 | The callme_startcall function in recordings/misc/callme_page.php in FreePBX 2.9, 2.10, and earlier allows remote attackers to execute arbitrary commands via the callmenum parameter in a c action. | 2 | 7.5 | High | 2017-01-19 | 2012-09-07 | View | |
| 49209 | CVE-2009-1947 | SQL injection vulnerability in the UnbDbEncode function in unb_lib/database.lib.php in Unclassified NewsBoard (UNB) 1.6.4 allows remote attackers to execute arbitrary SQL commands via the Query parameter in a search action to forum.php, a different vector than CVE-2005-3686. | 2 | 7.5 | High | 2017-01-07 | 2009-06-08 | View | |
| 51001 | CVE-2009-3834 | SQL injection vulnerability in the Photoblog (com_photoblog) component alpha 3 and alpha 3a for Joomla! allows remote attackers to execute arbitrary SQL commands via the category parameter in a blogs action to index.php. | 2 | 7.5 | High | 2017-01-07 | 2009-11-16 | View | |
| 51513 | CVE-2009-4390 | SQL injection vulnerability in the Car (car) extension 0.1.1 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | 2 | 7.5 | High | 2017-01-07 | 2009-12-23 | View |
Page 2586 of 17672, showing 5 records out of 88360 total, starting on record 12926, ending on 12930