NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
5316 | CVE-2008-5567 | Cross-site request forgery (CSRF) vulnerability in admin/ad_settings.php in Bonza Cart 1.10 and earlier allows remote attackers to change the admin password via a logout action in conjunction with the NewAdmin, NewPass1, and NewPass2 parameters. | 2 | 6.8 | Medium | 2017-01-03 | 2009-01-29 | View | |
5317 | CVE-2008-5568 | Cross-site request forgery (CSRF) vulnerability in admin/settings.php in IPN Pro 3 1.44 and earlier allows remote attackers to change the admin password via a logout action in conjunction with the admin_id, newpass_1, and newpass_2 parameters. | 2 | 6.8 | Medium | 2017-01-03 | 2009-01-29 | View | |
5318 | CVE-2008-5569 | Multiple cross-site scripting (XSS) vulnerabilities in PHPepperShop 1.4 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) index.php or (2) shop/kontakt.php, or (3) shop_kunden_mgmt.php or (4) SHOP_KONFIGURATION.php in shop/Admin/. | 2 | 4.3 | Medium | 2017-01-03 | 2009-01-29 | View | |
5319 | CVE-2008-5570 | Directory traversal vulnerability in index.php in PHP Multiple Newsletters 2.7, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter. | 2 | 6.8 | Medium | 2017-01-03 | 2009-03-18 | View | |
5320 | CVE-2008-5571 | SQL injection vulnerability in admin/login.asp in Professional Download Assistant 0.1 allows remote attackers to execute arbitrary SQL commands via the (1) uname parameter (aka user field) or the (2) psw parameter (aka passwd field). NOTE: some of these details are obtained from third party information. | 2 | 7.5 | High | 2017-01-03 | 2009-03-18 | View |
Page 1064 of 17672, showing 5 records out of 88360 total, starting on record 5316, ending on 5320