NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 47749 | CVE-2009-0417 | Cross-site scripting (XSS) vulnerability in the AgaviWebRouting::gen(null) method in Agavi 0.11 before 0.11.6 and 1.0 before 1.0.0 beta 8 allows remote attackers to inject arbitrary web script or HTML via a crafted URL with certain characters that are not properly handled by web browsers that do not strictly follow RFC 3986, such as Internet Explorer 6 and 7. | 2 | 4.3 | Medium | 2017-01-07 | 2009-03-13 | View | |
| 47751 | CVE-2009-0419 | Microsoft XML Core Services, as used in Microsoft Expression Web, Office, Internet Explorer 6 and 7, and other products, does not properly restrict access from web pages to Set-Cookie2 HTTP response headers, which allows remote attackers to obtain sensitive information from cookies via XMLHttpRequest calls, related to the HTTPOnly protection mechanism. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2008-4033. | 2 | 5 | Medium | 2017-01-07 | 2009-03-13 | View | |
| 3721 | CVE-2008-3859 | Davlin Thickbox Gallery 2 allows remote attackers to obtain the administrative username and MD5 password hash via a direct request to conf/admins.php. | 2 | 5 | Medium | 2017-01-03 | 2009-03-13 | View | |
| 6025 | CVE-2008-6294 | admin/Index.php in Acc Statistics 1.1 allows remote attackers to bypass authentication and gain administrative access by setting the username_cookie cookie to "admin." | 2 | 7.5 | High | 2017-01-03 | 2009-03-13 | View | |
| 6028 | CVE-2008-6297 | Cross-site scripting (XSS) vulnerability in order.php in DHCart allows remote attackers to inject arbitrary web script or HTML via the (1) domain and (2) d1 parameters. | 2 | 4.3 | Medium | 2017-01-03 | 2009-03-13 | View |
Page 2849 of 17672, showing 5 records out of 88360 total, starting on record 14241, ending on 14245