NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 49006 | CVE-2009-1737 | Directory traversal vulnerability in bom.php in MyPic 2.1 allows remote attackers to list files in arbitrary directories via a .. (dot dot) in the dir parameter. | 2 | 7.8 | High | 2017-01-07 | 2009-05-20 | View | |
| 48755 | CVE-2009-1482 | Multiple cross-site scripting (XSS) vulnerabilities in action/AttachFile.py in MoinMoin 1.8.2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) an AttachFile sub-action in the error_msg function or (2) multiple vectors related to package file errors in the upload_form function, different vectors than CVE-2009-0260. | 2 | 4.3 | Medium | 2017-01-07 | 2009-05-20 | View | |
| 48772 | CVE-2009-1499 | SQL injection vulnerability in the MailTo (aka com_mailto) component in Joomla! allows remote attackers to execute arbitrary SQL commands via the article parameter in index.php. NOTE: SecurityFocus states that this issue has been disputed by the vendor. | 2 | 7.5 | High | 2017-01-07 | 2009-05-20 | View | |
| 5579 | CVE-2008-5848 | The Advantech ADAM-6000 module has 00000000 as its default password, which makes it easier for remote attackers to obtain access through an HTTP session, and (1) monitor or (2) control the module"s Modbus/TCP I/O activity. | 2 | 10 | High | 2017-01-03 | 2009-05-20 | View | |
| 48844 | CVE-2009-1575 | Cross-site scripting (XSS) vulnerability in Drupal 5.x before 5.17 and 6.x before 6.11, as used in vbDrupal before 5.17.0, allows remote attackers to inject arbitrary web script or HTML via crafted UTF-8 byte sequences before the Content-Type meta tag, which are treated as UTF-7 by Internet Explorer 6 and 7. | 2 | 4.3 | Medium | 2017-01-07 | 2009-05-20 | View |
Page 3085 of 17672, showing 5 records out of 88360 total, starting on record 15421, ending on 15425