NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
49199  CVE-2009-1937  Cross-site scripting (XSS) vulnerability in the comment posting feature in LightNEasy 2.2.1 "no database" (aka flat) and 2.2.2 SQLite allows remote attackers to inject arbitrary web script or HTML via the (1) commentname (aka Author), (2) commentemail (aka Email), and (3) commentmessage (aka Comment) parameters. NOTE: some of these details are obtained from third party information.    4.3  Medium  2017-01-07  2009-06-08  View
49203  CVE-2009-1941  PAD Site Scripts 3.6 stores sensitive information under the web document root with insufficient access control, which allows remote attackers to download the database and obtain sensitive information via a direct request for dbbackup.txt.    Medium  2017-01-07  2009-06-08  View
49204  CVE-2009-1942  Cross-site scripting (XSS) vulnerability in the Quiz module 5.x, 6.x-2.x before 6.x-2.2, and 6.x-3.x before 6.x-3.0, a module for Drupal, allows remote authenticated users, with create quizzes or quiz questions access, to inject arbitrary web script or HTML via unspecified vectors.    3.5  Low  2017-01-07  2009-06-08  View
49206  CVE-2009-1944  Stack-based buffer overflow in AIMP 2.51 build 330 allows remote attackers to execute arbitrary code via an MP3 file with a long ID3 tag.    9.3  High  2017-01-07  2009-06-08  View
49208  CVE-2009-1946  PHP remote file inclusion vulnerability in latestposts.php in AdaptBB 1.0, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the forumspath parameter.    6.8  Medium  2017-01-07  2009-06-08  View

Page 3108 of 17672, showing 5 records out of 88360 total, starting on record 15536, ending on 15540

Actions