NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
49378  CVE-2009-2116  Directory traversal vulnerability in admin.php in SkyBlueCanvas 1.1 r237 allows remote authenticated administrators to list directory contents via a .. (dot dot) in the dir parameter.    Medium  2017-01-07  2009-06-22  View
49384  CVE-2009-2122  SQL injection vulnerability in viewimg.php in the Paolo Palmonari Photoracer plugin 1.0 for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter.    7.5  High  2017-01-07  2009-06-22  View
49386  CVE-2009-2124  Directory traversal vulnerability in page.php in Elvin 1.2.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the id parameter.    7.5  High  2017-01-07  2009-06-22  View
49388  CVE-2009-2126  Cross-site scripting (XSS) vulnerability in close_bug.php in Elvin before 1.2.1 allows remote attackers to inject arbitrary web script or HTML via the title (aka subject) field.    4.3  Medium  2017-01-07  2009-06-22  View
49389  CVE-2009-2127  Cross-site scripting (XSS) vulnerability in show_activity.php in Elvin 1.2.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter.    4.3  Medium  2017-01-07  2009-06-22  View

Page 3149 of 17672, showing 5 records out of 88360 total, starting on record 15741, ending on 15745

Actions