NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
5956 | CVE-2008-6225 | ** DISPUTED ** SQL injection vulnerability in info.php in Mole Group Airline Ticket Sale Script allows remote attackers to execute arbitrary SQL commands via the flight parameter. NOTE: the vendor has disputed this issue, stating "crazy hackers and so named Security companies [spread] out such false informations. Such scripts or versions [do not] exist." | 2 | 7.5 | High | 2017-01-03 | 2011-03-07 | View | |
5957 | CVE-2008-6226 | SQL injection vulnerability in moreinfo.php in Pre Projects PHP Auto Listings Script, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the itemno parameter. | 2 | 6.8 | Medium | 2017-01-03 | 2011-03-07 | View | |
5958 | CVE-2008-6227 | SQL injection vulnerability in buyer_detail.php in Pre Multi-Vendor Shopping Malls allows remote attackers to execute arbitrary SQL commands via the (1) sid and (2) cid parameters. | 2 | 7.5 | High | 2017-01-03 | 2011-03-07 | View | |
5959 | CVE-2008-6228 | Pre Multi-Vendor Shopping Malls allows remote attackers to bypass authentication and gain administrative access by setting the (1) adminname and the (2) adminid cookies to "admin". | 2 | 7.5 | High | 2017-01-03 | 2011-03-07 | View | |
5960 | CVE-2008-6229 | Cross-site scripting (XSS) vulnerability in the administrative interface in Drupal Content Construction Kit (CCK) 5.x before 5.x-1.10 and 6.x before 6.x-2.0, a module for Drupal, allows remote authenticated users with "administer content" permissions to inject arbitrary web script or HTML via (1) field labels and (2) content-type names. | 2 | 3.5 | Low | 2017-01-03 | 2011-03-07 | View |
Page 1192 of 17672, showing 5 records out of 88360 total, starting on record 5956, ending on 5960