NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
50222  CVE-2009-3005  Lunascape 5.1.3 and 5.1.4 allows remote attackers to spoof the address bar, via window.open with a relative URI, to show an arbitrary URL on the web site visited by the victim, as demonstrated by a visit to an attacker-controlled web page, which triggers a spoofed login form for the site containing that page. NOTE: a related attack was reported in which an arbitrary file: URL is shown.    4.3  Medium  2017-01-07  2009-09-05  View
50478  CVE-2009-3273  iPhone Mail in Apple iPhone OS, and iPhone OS for iPod touch, does not validate X.509 certificates, which allows man-in-the-middle attackers to spoof arbitrary SSL e-mail servers via a crafted certificate.    7.5  High  2017-01-07  2009-09-22  View
50734  CVE-2009-3534  Directory traversal vulnerability in index.php in LionWiki 3.0.3, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter.    6.8  Medium  2017-01-07  2009-10-05  View
50990  CVE-2009-3822  PHP remote file inclusion vulnerability in Fiji Web Design Ajax Chat (com_ajaxchat) component 1.0 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[mosConfig_absolute_path] parameter to tests/ajcuser.php.    7.5  High  2017-01-07  2009-10-28  View
51246  CVE-2009-4096  RADIO istek scripti 2.5 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain user credentials via a direct request for estafresgaftesantusyan.inc.    7.5  High  2017-01-07  2009-12-02  View

Page 2816 of 17672, showing 5 records out of 88360 total, starting on record 14076, ending on 14080

Actions