NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 49387 | CVE-2009-2125 | delete_bug.php in Elvin before 1.2.1 does not require administrative privileges, which allows remote authenticated users to bypass intended access restrictions and delete arbitrary bugs. | 2 | 4 | Medium | 2017-01-07 | 2009-06-23 | View | |
| 49396 | CVE-2009-2134 | pivot/tb.php in Pivot 1.40.4 and 1.40.7 allows remote attackers to obtain sensitive information via an invalid url parameter, which reveals the installation path in an error message. | 2 | 5 | Medium | 2017-01-07 | 2009-06-23 | View | |
| 49403 | CVE-2009-2141 | Multiple cross-site scripting (XSS) vulnerabilities in TBDev.NET 01-01-08 allow remote attackers to inject arbitrary web script or HTML via (1) the returnto parameter to makepoll.php, (2) the returnto parameter in a delete action to polls.php, or the (3) Info or (4) Avatar field to my.php. | 2 | 4.3 | Medium | 2017-01-07 | 2009-06-23 | View | |
| 49404 | CVE-2009-2142 | Multiple SQL injection vulnerabilities in admin/index.asp in Zip Store Chat 4.0 and 5.0 allow remote attackers to execute arbitrary SQL commands via the (1) login and (2) senha parameters. | 2 | 7.5 | High | 2017-01-07 | 2009-06-23 | View | |
| 49407 | CVE-2009-2145 | Multiple cross-site scripting (XSS) vulnerabilities in transLucid 1.75 allow remote attackers to inject arbitrary web script or HTML via the (a) NodeID and (b) action parameters to the default URI, and the (c) NodeID parameter to the default URI for the admin section; and allow remote authenticated users to inject arbitrary web script or HTML via the (d) Title (aka page name) and (e) Url fields in a (1) new or (2) modified page. | 2 | 4.3 | Medium | 2017-01-07 | 2009-06-23 | View |
Page 3162 of 17672, showing 5 records out of 88360 total, starting on record 15806, ending on 15810