NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
49682  CVE-2009-2437  Multiple cross-site scripting (XSS) vulnerabilities in index.php in Rentventory 1.0.1 allow remote attackers to inject arbitrary web script or HTML via the (1) username (aka Login) and (2) password parameters in a login action.    4.3  Medium  2017-01-07  2009-07-13  View
49938  CVE-2009-2697  The Red Hat build script for the GNOME Display Manager (GDM) before 2.16.0-56 on Red Hat Enterprise Linux (RHEL) 5 omits TCP Wrapper support, which might allow remote attackers to bypass intended access restrictions via XDMCP connections, a different vulnerability than CVE-2007-5079.    6.8  Medium  2017-01-07  2010-08-21  View
51218  CVE-2009-4066  Multiple cross-site request forgery (CSRF) vulnerabilities in the "My Account" feature in PHPList Integration module 5 before 5.x-1.2 and 6 before 6.x-1.1 for Drupal allow remote attackers to hijack the authentication of arbitrary users via vectors related to (1) subscribing or (2) unsubscribing to mailing lists.    6.8  Medium  2017-01-07  2009-11-24  View
51474  CVE-2009-4351  SQL injection vulnerability in ADMIN/loginaction.php in WSCreator 1.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the Email (aka username) parameter.    6.8  Medium  2017-01-07  2009-12-18  View
51986  CVE-2009-4869  Cross-site scripting (XSS) vulnerability in index.php in Nasim Guest Book 1.2 allows remote attackers to inject arbitrary web script or HTML via the page parameter.    4.3  Medium  2017-01-07  2010-05-11  View

Page 681 of 17672, showing 5 records out of 88360 total, starting on record 3401, ending on 3405

Actions