NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 49590 | CVE-2009-2342 | Cross-site scripting (XSS) vulnerability in admin.php (aka the login page) in Content Management Made Easy (CMME) before 1.22 allows remote attackers to inject arbitrary web script or HTML via the username field. | 2 | 4.3 | Medium | 2017-01-07 | 2009-07-08 | View | |
| 49592 | CVE-2009-2344 | The web-based management interfaces in Sourcefire Defense Center (DC) and 3D Sensor before 4.8.2 allow remote authenticated users to gain privileges via a $admin value for the admin parameter in an edit action to admin/user/user.cgi and unspecified other components. | 2 | 9 | High | 2017-01-07 | 2009-07-08 | View | |
| 49593 | CVE-2009-2345 | Multiple SQL injection vulnerabilities in ClanSphere before 2009.0.1 allow remote attackers to execute arbitrary SQL commands via unknown parameters to the gbook module and unspecified other components. | 2 | 7.5 | High | 2017-01-07 | 2009-07-08 | View | |
| 49601 | CVE-2009-2354 | SQL injection vulnerability in the auth_checkpass function in the login page in NullLogic Groupware 1.2.7 allows remote attackers to execute arbitrary SQL commands via the username parameter. | 2 | 7.5 | High | 2017-01-07 | 2009-07-08 | View | |
| 49605 | CVE-2009-2358 | TekRADIUS 3.0 uses BUILTINUsers:R permissions for the TekRADIUS.ini file, which allows local users to obtain obfuscated database credentials by reading this file. | 2 | 4.6 | Medium | 2017-01-07 | 2009-07-08 | View |
Page 3199 of 17672, showing 5 records out of 88360 total, starting on record 15991, ending on 15995