NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
50950 | CVE-2009-3781 | The filefield_file_download function in FileField 6.x-3.1, a module for Drupal, does not properly check node-access permissions for Drupal core private files, which allows remote attackers to access unauthorized files via unspecified vectors. | 2 | 7.5 | High | 2017-01-07 | 2009-10-27 | View | |
51462 | CVE-2009-4339 | SQL injection vulnerability in the Subscription (mf_subscription) extension 0.2.2 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unknown vectors. | 2 | 7.5 | High | 2017-01-07 | 2010-06-29 | View | |
51718 | CVE-2009-4601 | Cross-site scripting (XSS) vulnerability in basic_search_result.php in Zeeways ZeeJobsite 3x allows remote attackers to inject arbitrary web script or HTML via the title parameter. | 2 | 4.3 | Medium | 2017-01-07 | 2010-01-13 | View | |
51974 | CVE-2009-4857 | Cross-site scripting (XSS) vulnerability in login.php in PHP Photo Vote 1.3F allows remote attackers to inject arbitrary web script or HTML via the page parameter. | 2 | 4.3 | Medium | 2017-01-07 | 2010-05-11 | View | |
52230 | CVE-2009-5135 | The Java XML parser in Echo before 2.1.1 and 3.x before 3.0.b6 allows remote attackers to read arbitrary files via a request containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. | 2 | 5 | Medium | 2017-01-07 | 2013-05-02 | View |
Page 465 of 17672, showing 5 records out of 88360 total, starting on record 2321, ending on 2325