NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
49295  CVE-2009-2033  Cross-site scripting (XSS) vulnerability in index.php in Yogurt 0.3 allows remote attackers to inject arbitrary web script or HTML via the msg parameter.    4.3  Medium  2017-01-07  2009-06-20  View
49296  CVE-2009-2034  SQL injection vulnerability in writemessage.php in Yogurt 0.3, when register_globals is enabled, allows remote authenticated users to execute arbitrary SQL commands via the original parameter.    Medium  2017-01-07  2009-06-20  View
49298  CVE-2009-2036  SQL injection vulnerability in index.php in Open Biller 0.1 allows remote attackers to execute arbitrary SQL commands via the username parameter.    7.5  High  2017-01-07  2009-06-20  View
49273  CVE-2009-2011  Worldweaver DX Studio Player 3.0.29.0, 3.0.22.0, 3.0.12.0, and probably other versions before 3.0.29.1, when used as a plug-in for Firefox, does not restrict access to the shell.execute JavaScript API method, which allows remote attackers to execute arbitrary commands via a .dxstudio file that invokes this method.    9.3  High  2017-01-07  2009-06-22  View
49377  CVE-2009-2115  admin.php in SkyBlueCanvas 1.1 r237 allows remote authenticated administrators to obtain sensitive information via an invalid id parameter, which reveals the installation path in an error message.    6.8  Medium  2017-01-07  2009-06-22  View

Page 3148 of 17672, showing 5 records out of 88360 total, starting on record 15736, ending on 15740

Actions