NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
49178 | CVE-2009-1913 | SQL injection vulnerability in manager.php in LuxBum 0.5.5, when magic_quotes_gpc is disabled and dotclear authentication is used, allows remote attackers to execute arbitrary SQL commands via the username parameter in a login action. | 2 | 5.1 | Medium | 2017-01-07 | 2009-06-05 | View | |
49434 | CVE-2009-2172 | Cross-site scripting (XSS) vulnerability in forum/radioandtv.php in the Radio and TV Player addon for vBulletin allows remote registered users to inject arbitrary web script or HTML via the station parameter. | 2 | 4.3 | Medium | 2017-01-07 | 2009-06-24 | View | |
49690 | CVE-2009-2445 | Oracle iPlanet Web Server (formerly Sun Java System Web Server or Sun ONE Web Server) 6.1 before SP12, and 7.0 through Update 6, when running on Windows, allows remote attackers to read arbitrary JSP files via an alternate data stream syntax, as demonstrated by a .jsp::$DATA URI. | 2 | 5 | Medium | 2017-01-07 | 2011-08-29 | View | |
49946 | CVE-2009-2705 | CA SiteMinder allows remote attackers to bypass cross-site scripting (XSS) protections for J2EE applications via a request containing non-canonical, "overlong Unicode" in place of blacklisted characters. | 2 | 4.3 | Medium | 2017-01-07 | 2009-08-11 | View | |
50714 | CVE-2009-3513 | Multiple cross-site scripting (XSS) vulnerabilities in Pilot Group (PG) eTraining allow remote attackers to inject arbitrary web script or HTML via (1) the cat_id parameter to courses_login.php, the id parameter to (2) news_read.php or (3) lessons_login.php, or (4) the cur parameter in a start action to lessons_login.php. | 2 | 4.3 | Medium | 2017-01-07 | 2009-10-02 | View |
Page 963 of 17672, showing 5 records out of 88360 total, starting on record 4811, ending on 4815