NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
49590  CVE-2009-2342  Cross-site scripting (XSS) vulnerability in admin.php (aka the login page) in Content Management Made Easy (CMME) before 1.22 allows remote attackers to inject arbitrary web script or HTML via the username field.    4.3  Medium  2017-01-07  2009-07-08  View
49592  CVE-2009-2344  The web-based management interfaces in Sourcefire Defense Center (DC) and 3D Sensor before 4.8.2 allow remote authenticated users to gain privileges via a $admin value for the admin parameter in an edit action to admin/user/user.cgi and unspecified other components.    High  2017-01-07  2009-07-08  View
49593  CVE-2009-2345  Multiple SQL injection vulnerabilities in ClanSphere before 2009.0.1 allow remote attackers to execute arbitrary SQL commands via unknown parameters to the gbook module and unspecified other components.    7.5  High  2017-01-07  2009-07-08  View
49601  CVE-2009-2354  SQL injection vulnerability in the auth_checkpass function in the login page in NullLogic Groupware 1.2.7 allows remote attackers to execute arbitrary SQL commands via the username parameter.    7.5  High  2017-01-07  2009-07-08  View
49605  CVE-2009-2358  TekRADIUS 3.0 uses BUILTINUsers:R permissions for the TekRADIUS.ini file, which allows local users to obtain obfuscated database credentials by reading this file.    4.6  Medium  2017-01-07  2009-07-08  View

Page 3199 of 17672, showing 5 records out of 88360 total, starting on record 15991, ending on 15995

Actions