NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 49011 | CVE-2009-1742 | code.php in PC4Arb Pc4 Uploader 9.0 and earlier makes it easier for remote attackers to conduct SQL injection attacks via crafted keyword sequences that are removed from a filter in the id parameter in a banner action, as demonstrated via the "UNIunionON" string, which is collapsed into "UNION" by the filter_sql function. | 2 | 7.5 | High | 2017-01-07 | 2009-05-21 | View | |
| 49016 | CVE-2009-1747 | SQL injection vulnerability in index.php in 26th Avenue bSpeak 1.10 allows remote attackers to execute arbitrary SQL commands via the forumid parameter in a post action. | 2 | 7.5 | High | 2017-01-07 | 2009-05-22 | View | |
| 49021 | CVE-2009-1752 | exJune Office Message System 1 does not properly restrict access to (1) configure.asp and (2) addmessage2.asp, which allows remote attackers to gain privileges a direct request. NOTE: some of these details are obtained from third party information. | 2 | 7.5 | High | 2017-01-07 | 2009-05-22 | View | |
| 49026 | CVE-2009-1757 | Cross-site request forgery (CSRF) vulnerability in Transmission 1.5 before 1.53 and 1.6 before 1.61 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors. | 2 | 6.8 | Medium | 2017-01-07 | 2009-05-22 | View | |
| 48104 | CVE-2009-0786 | ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This was originally intended for a report about TCP Wrappers and the hosts_ctl API function, but further investigation showed that this was documented behavior by that function. Notes: Future CVE identifiers might be assigned to applications that mis-use the API in a security-relevant fashion. | 1 | 2017-01-07 | 2009-05-22 | View |
Page 3087 of 17672, showing 5 records out of 88360 total, starting on record 15431, ending on 15435