NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 49499 | CVE-2009-2237 | Unspecified vulnerability in Views Bulk Operations 5.x-1.x before 5.x-1.4 and 6.x-1.x before 6.x-1.7, a module for Drupal, allows remote attackers to bypass intended access restrictions and modify "nodes or classes of nodes" via unknown vectors, probably related to registered procedures (aka actions). | 2 | 7.5 | High | 2017-01-07 | 2009-06-29 | View | |
| 49500 | CVE-2009-2238 | Unrestricted file upload vulnerability in includes/shared_scripts/wysiwyg_editor/assetmanager/assetmanager.asp in DMXReady Registration Manager 1.1 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in assets/webblogmanager. | 2 | 6.8 | Medium | 2017-01-07 | 2009-06-29 | View | |
| 49503 | CVE-2009-2241 | Cross-site scripting (XSS) vulnerability in search.asp in ASP Inline Corporate Calendar allows remote attackers to inject arbitrary web script or HTML via the keyword parameter. | 2 | 4.3 | Medium | 2017-01-07 | 2009-06-29 | View | |
| 49504 | CVE-2009-2242 | SQL injection vulnerability in active_appointments.asp in ASP Inline Corporate Calendar allows remote attackers to execute arbitrary SQL commands via the order parameter. | 2 | 6.8 | Medium | 2017-01-07 | 2009-06-29 | View | |
| 49505 | CVE-2009-2243 | SQL injection vulnerability in active_appointments.asp in ASP Inline Corporate Calendar allows remote attackers to execute arbitrary SQL commands via the sortby parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | 2 | 7.5 | High | 2017-01-07 | 2009-06-29 | View |
Page 3175 of 17672, showing 5 records out of 88360 total, starting on record 15871, ending on 15875