NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
48729  CVE-2009-1453  SQL injection vulnerability in class.eport.php in Tiny Blogr 1.0.0 rc4, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the txtUsername parameter (aka the Username field). NOTE: some of these details are obtained from third party information.    6.8  Medium  2017-01-07  2009-04-28  View
49753  CVE-2009-2508  The single sign-on implementation in Active Directory Federation Services (ADFS) in Microsoft Windows Server 2003 SP2 and Server 2008 Gold and SP2 does not properly remove credentials at the end of a network session, which allows physically proximate attackers to obtain the credentials of a previous user of the same web browser by using data from the browser"s cache, aka "Single Sign On Spoofing in ADFS Vulnerability."    6.9  Medium  2017-01-07  2010-08-21  View
51545  CVE-2009-4422  Multiple cross-site scripting (XSS) vulnerabilities in the GetURLArguments function in jpgraph.php in Aditus Consulting JpGraph 3.0.6 allow remote attackers to inject arbitrary web script or HTML via a key to csim_in_html_ex1.php, and other unspecified vectors.    4.3  Medium  2017-01-07  2009-12-31  View
51801  CVE-2009-4684  Cross-site scripting (XSS) vulnerability in index.php in EZodiak allows remote attackers to inject arbitrary web script or HTML via the sign parameter.    4.3  Medium  2017-01-07  2010-03-11  View
52057  CVE-2009-4942  Cross-site request forgery (CSRF) vulnerability in ACollab 1.2 allows remote attackers to hijack the authentication of arbitrary users for requests that add personal agenda items.    4.3  Medium  2017-01-07  2010-07-22  View

Page 3215 of 17672, showing 5 records out of 88360 total, starting on record 16071, ending on 16075

Actions