NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
40249  CVE-2013-4701  Auth/Yadis/XML.php in PHP OpenID Library 2.2.2 and earlier allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via XRDS data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.    7.5  High  2017-01-18  2016-11-28  View
46137  CVE-2012-4869  The callme_startcall function in recordings/misc/callme_page.php in FreePBX 2.9, 2.10, and earlier allows remote attackers to execute arbitrary commands via the callmenum parameter in a c action.    7.5  High  2017-01-19  2012-09-07  View
49209  CVE-2009-1947  SQL injection vulnerability in the UnbDbEncode function in unb_lib/database.lib.php in Unclassified NewsBoard (UNB) 1.6.4 allows remote attackers to execute arbitrary SQL commands via the Query parameter in a search action to forum.php, a different vector than CVE-2005-3686.    7.5  High  2017-01-07  2009-06-08  View
51001  CVE-2009-3834  SQL injection vulnerability in the Photoblog (com_photoblog) component alpha 3 and alpha 3a for Joomla! allows remote attackers to execute arbitrary SQL commands via the category parameter in a blogs action to index.php.    7.5  High  2017-01-07  2009-11-16  View
51513  CVE-2009-4390  SQL injection vulnerability in the Car (car) extension 0.1.1 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.    7.5  High  2017-01-07  2009-12-23  View

Page 2586 of 17672, showing 5 records out of 88360 total, starting on record 12926, ending on 12930

Actions