NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 49375 | CVE-2009-2113 | Multiple SQL injection vulnerabilities in FretsWeb 1.2 allow remote attackers to execute arbitrary SQL commands via the (1) name parameter to player.php and the (2) hash parameter to song.php. | 2 | 7.5 | High | 2017-01-07 | 2009-06-24 | View | |
| 49379 | CVE-2009-2117 | uye_paneli.php in phPortal 1.0 allows remote attackers to bypass authentication and obtain administrative access by setting the kulladi cookie to a valid username. | 2 | 7.5 | High | 2017-01-07 | 2009-06-24 | View | |
| 49380 | CVE-2009-2118 | Integer overflow in IrfanView 4.23, when the resampling or screen fitting option is enabled, allows remote attackers to execute arbitrary code via a crafted TIFF 1 BPP image, which triggers a heap-based buffer overflow. | 2 | 6.8 | Medium | 2017-01-07 | 2009-06-24 | View | |
| 49405 | CVE-2009-2143 | PHP remote file inclusion vulnerability in firestats-wordpress.php in the FireStats plugin before 1.6.2-stable for WordPress allows remote attackers to execute arbitrary PHP code via a URL in the fs_javascript parameter. | 2 | 7.5 | High | 2017-01-07 | 2009-06-24 | View | |
| 49408 | CVE-2009-2146 | Unrestricted file upload vulnerability in the Compose Email feature in the Emails module in Sugar Community Edition (aka SugarCRM) before 5.2f allows remote authenticated users to execute arbitrary code by uploading a file with only an extension in its name, then accessing the file via a direct request to a modified filename under cache/modules/Emails/, as demonstrated using .php as the entire original name. | 2 | 6 | Medium | 2017-01-07 | 2009-06-25 | View |
Page 3167 of 17672, showing 5 records out of 88360 total, starting on record 15831, ending on 15835