NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 48681 | CVE-2009-1405 | Directory traversal vulnerability in index.php in PastelCMS 0.8.0, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the set_lng parameter. | 2 | 6.8 | Medium | 2017-01-07 | 2009-04-24 | View | |
| 48683 | CVE-2009-1407 | Directory traversal vulnerability in config.php in NotFTP 1.3.1 allows remote attackers to read arbitrary files via a .. (dot dot) in a certain languages[][file] parameter. | 2 | 6.8 | Medium | 2017-01-07 | 2009-04-24 | View | |
| 48684 | CVE-2009-1408 | Cross-site scripting (XSS) vulnerability in webSPELL 4.2.0c allows remote attackers to inject arbitrary web script or HTML allows remote attackers to inject arbitrary web script or HTML via Javascript events such as onmouseover in nested BBcode tags, as demonstrated using (1) email, (2) img, and (3) url tags. | 2 | 4.3 | Medium | 2017-01-07 | 2009-04-24 | View | |
| 48685 | CVE-2009-1409 | SQL injection vulnerability in usersettings.php in e107 0.7.15 and earlier, when "Extended User Fields" is enabled and magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the hide parameter, a different vector than CVE-2005-4224 and CVE-2008-5320. | 2 | 5.1 | Medium | 2017-01-07 | 2009-04-24 | View | |
| 48686 | CVE-2009-1410 | SQL injection vulnerability in index.php in Quick.Cms.Lite 0.5 allows remote attackers to execute arbitrary SQL commands via the id parameter. | 2 | 7.5 | High | 2017-01-07 | 2009-04-24 | View |
Page 3011 of 17672, showing 5 records out of 88360 total, starting on record 15051, ending on 15055