NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
49682 | CVE-2009-2437 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in Rentventory 1.0.1 allow remote attackers to inject arbitrary web script or HTML via the (1) username (aka Login) and (2) password parameters in a login action. | 2 | 4.3 | Medium | 2017-01-07 | 2009-07-13 | View | |
49938 | CVE-2009-2697 | The Red Hat build script for the GNOME Display Manager (GDM) before 2.16.0-56 on Red Hat Enterprise Linux (RHEL) 5 omits TCP Wrapper support, which might allow remote attackers to bypass intended access restrictions via XDMCP connections, a different vulnerability than CVE-2007-5079. | 2 | 6.8 | Medium | 2017-01-07 | 2010-08-21 | View | |
51218 | CVE-2009-4066 | Multiple cross-site request forgery (CSRF) vulnerabilities in the "My Account" feature in PHPList Integration module 5 before 5.x-1.2 and 6 before 6.x-1.1 for Drupal allow remote attackers to hijack the authentication of arbitrary users via vectors related to (1) subscribing or (2) unsubscribing to mailing lists. | 2 | 6.8 | Medium | 2017-01-07 | 2009-11-24 | View | |
51474 | CVE-2009-4351 | SQL injection vulnerability in ADMIN/loginaction.php in WSCreator 1.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the Email (aka username) parameter. | 2 | 6.8 | Medium | 2017-01-07 | 2009-12-18 | View | |
51986 | CVE-2009-4869 | Cross-site scripting (XSS) vulnerability in index.php in Nasim Guest Book 1.2 allows remote attackers to inject arbitrary web script or HTML via the page parameter. | 2 | 4.3 | Medium | 2017-01-07 | 2010-05-11 | View |
Page 681 of 17672, showing 5 records out of 88360 total, starting on record 3401, ending on 3405