NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 49059 | CVE-2009-1790 | Cross-site scripting (XSS) vulnerability in CGI RESCUE Trees before 2.11 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters. | 2 | 4.3 | Medium | 2017-01-07 | 2009-05-27 | View | |
| 49031 | CVE-2009-1762 | Multiple cross-site scripting (XSS) vulnerabilities in the WebAccess login page (aka gw/webacc) in Novell GroupWise 7.x before 7.03 HP2 allow remote attackers to inject arbitrary web script or HTML via the (1) GWAP.version or (2) User.Theme (aka User.Theme.index) parameter. | 2 | 4.3 | Medium | 2017-01-07 | 2009-05-28 | View | |
| 6546 | CVE-2008-6815 | mykdownload.php in MyKtools 2.4 does not require administrative authentication, which allows remote attackers to read a database backup by making a direct request, and then sending an unspecified request to the download page for the backup. | 2 | 5 | Medium | 2017-01-03 | 2009-05-28 | View | |
| 6547 | CVE-2008-6816 | Eaton MGEOPS Network Shutdown Module before 3.10 Build 13 allows remote attackers to execute arbitrary code by adding a custom action to the MGE frontend via pane_actionbutton.php, and then executing this action via exec_action.php. | 2 | 10 | High | 2017-01-03 | 2009-05-28 | View | |
| 49065 | CVE-2009-1799 | Multiple SQL injection vulnerabilities in the getGalleryImage function in st_admin/gallery_output.php in ST-Gallery 0.1 alpha, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) gallery_category or (2) gallery_show parameter to example.php. | 2 | 6.8 | Medium | 2017-01-07 | 2009-05-28 | View |
Page 3095 of 17672, showing 5 records out of 88360 total, starting on record 15471, ending on 15475