NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 48860 | CVE-2009-1591 | CRLF injection vulnerability in CGI RESCUE Web Mailer before 1.04 allows remote attackers to inject arbitrary HTTP headers, and conduct cross-site scripting (XSS) or HTTP response splitting attacks, via CRLF sequences in an unspecified web form. | 2 | 4.3 | Medium | 2017-01-07 | 2009-05-23 | View | |
| 48862 | CVE-2009-1593 | Armorlogic Profense Web Application Firewall before 2.2.22, and 2.4.x before 2.4.4, does not properly implement the "negative model," which allows remote attackers to conduct cross-site scripting (XSS) attacks via a modified end tag of a SCRIPT element. | 2 | 4.3 | Medium | 2017-01-07 | 2009-05-23 | View | |
| 48873 | CVE-2009-1604 | Unspecified vulnerability in LimeSurvey before 1.82 allows remote attackers to execute commands and obtain sensitive data via unknown attack vectors related to /admin/remotecontrol/. | 2 | 7.5 | High | 2017-01-07 | 2009-05-23 | View | |
| 48878 | CVE-2009-1609 | Unrestricted file upload vulnerability in admin/uploadform.asp in Battle Blog 1.25 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file. | 2 | 6.8 | Medium | 2017-01-07 | 2009-05-23 | View | |
| 49034 | CVE-2009-1765 | Multiple directory traversal vulnerabilities in pluck 4.6.2, when register_globals is enabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the langpref parameter to (1) data/modules/contactform/module_info.php, (2) data/modules/blog/module_info.php, and (3) data/modules/albums/module_info.php, different vectors than CVE-2008-3194. | 2 | 6.8 | Medium | 2017-01-07 | 2009-05-24 | View |
Page 3092 of 17672, showing 5 records out of 88360 total, starting on record 15456, ending on 15460