NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
5956  CVE-2008-6225  ** DISPUTED ** SQL injection vulnerability in info.php in Mole Group Airline Ticket Sale Script allows remote attackers to execute arbitrary SQL commands via the flight parameter. NOTE: the vendor has disputed this issue, stating "crazy hackers and so named Security companies [spread] out such false informations. Such scripts or versions [do not] exist."    7.5  High  2017-01-03  2011-03-07  View
5957  CVE-2008-6226  SQL injection vulnerability in moreinfo.php in Pre Projects PHP Auto Listings Script, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the itemno parameter.    6.8  Medium  2017-01-03  2011-03-07  View
5958  CVE-2008-6227  SQL injection vulnerability in buyer_detail.php in Pre Multi-Vendor Shopping Malls allows remote attackers to execute arbitrary SQL commands via the (1) sid and (2) cid parameters.    7.5  High  2017-01-03  2011-03-07  View
5959  CVE-2008-6228  Pre Multi-Vendor Shopping Malls allows remote attackers to bypass authentication and gain administrative access by setting the (1) adminname and the (2) adminid cookies to "admin".    7.5  High  2017-01-03  2011-03-07  View
5960  CVE-2008-6229  Cross-site scripting (XSS) vulnerability in the administrative interface in Drupal Content Construction Kit (CCK) 5.x before 5.x-1.10 and 6.x before 6.x-2.0, a module for Drupal, allows remote authenticated users with "administer content" permissions to inject arbitrary web script or HTML via (1) field labels and (2) content-type names.    3.5  Low  2017-01-03  2011-03-07  View

Page 1192 of 17672, showing 5 records out of 88360 total, starting on record 5956, ending on 5960

Actions