NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
49039  CVE-2009-1770  Directory traversal vulnerability in includes/database/examples/addressbook.php in Flyspeck CMS 6.8 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter.    7.5  High  2017-01-07  2009-06-09  View
49040  CVE-2009-1771  index.php in Flyspeck CMS 6.8 does not require administrative authentication for the updateExistingContent action, which allows remote attackers to create or modify admin accounts via the (1) users[fullname], (2) users[email], (3) users[role_id], (4) users[username], and (5) users[password] parameters.    7.5  High  2017-01-07  2009-06-09  View
48024  CVE-2009-0703  SQL injection vulnerability in bview.asp in ASPThai.Net Webboard 6.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.    7.5  High  2017-01-07  2009-06-09  View
6042  CVE-2008-6311  SQL injection vulnerability in view.php in Butterfly Organizer 2.0.1 allows remote attackers to execute arbitrary SQL commands via the mytable parameter. NOTE: the id vector is covered by another CVE name.    7.5  High  2017-01-03  2009-06-09  View
6557  CVE-2008-6826  dhtml.pl in MHF Media Pro allows remote attackers to execute arbitrary commands via shell metacharacters in the page parameter, as demonstrated using the (1) advert_top.htm or (2) advert_login.htm pages.    10  High  2017-01-03  2009-06-09  View

Page 3122 of 17672, showing 5 records out of 88360 total, starting on record 15606, ending on 15610

Actions