NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
47793  CVE-2009-0461  Whole Hog Password Protect: Enhanced 1.x allows remote attackers to bypass authentication and obtain administrative access via an integer value in the adminid cookie.    7.5  High  2017-01-07  2009-03-06  View
47794  CVE-2009-0462  Multiple SQL injection vulnerabilities in customer_login_check.asp in ClickTech ClickCart 6.0 allow remote attackers to execute arbitrary SQL commands via (1) the txtEmail parameter (aka E-MAIL field) or (2) the txtPassword parameter (aka password field) to customer_login.asp. NOTE: some of these details are obtained from third party information.    7.5  High  2017-01-07  2009-03-06  View
47796  CVE-2009-0464  PHP remote file inclusion vulnerability in includes/header.php in Groone GBook 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the abspath parameter.    5.1  Medium  2017-01-07  2009-03-06  View
47797  CVE-2009-0465  The SaveDoc method in the All_In_The_Box.AllBox ActiveX control in ALL_IN_THE_BOX.OCX in Synactis ALL In-The-Box ActiveX 3 allows remote attackers to create and overwrite arbitrary files via an argument ending in a "" character, which bypasses the intended .box filename extension, as demonstrated by a C:oot.ini argument.    9.3  High  2017-01-07  2009-03-06  View
47798  CVE-2009-0466  Cross-site scripting (XSS) vulnerability in Vivvo CMS before 4.1.1 allows remote attackers to inject arbitrary web script or HTML via a URI that triggers a 404 Page Not Found response.    4.3  Medium  2017-01-07  2009-03-06  View

Page 2835 of 17672, showing 5 records out of 88360 total, starting on record 14171, ending on 14175

Actions