NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
6711 | CVE-2008-6980 | SQL injection vulnerability in as_archives.php in phpAdultSite CMS, possibly 2.3.2, allows remote attackers to execute arbitrary SQL commands via the results_per_page parameter to index.php. NOTE: some of these details are obtained from third party information. | 2 | 7.5 | High | 2017-01-03 | 2009-08-19 | View | |
6712 | CVE-2008-6981 | index.php in phpAdultSite CMS, possibly 2.3.2, allows remote attackers to obtain the full installation path via an invalid results_per_page parameter, which leaks the path in an error message. NOTE: this issue might be resultant from a separate SQL injection vulnerability. | 2 | 5 | Medium | 2017-01-03 | 2009-08-19 | View | |
6713 | CVE-2008-6982 | Cross-site scripting (XSS) vulnerability in index.php in devalcms 1.4a allows remote attackers to inject arbitrary web script or HTML via the currentpath parameter. | 2 | 4.3 | Medium | 2017-01-03 | 2009-08-19 | View | |
6714 | CVE-2008-6983 | modules/tool/hitcounter.php in devalcms 1.4a allows remote attackers to execute arbitrary PHP code via the HTTP Referer header with a target file specified in the gv_folder_data parameter, as demonstrated by modifying modules/tool/url2header.php. | 2 | 7.5 | High | 2017-01-03 | 2009-08-21 | View | |
6715 | CVE-2008-6984 | Plesk 8.6.0, when short mail login names (SHORTNAMES) are enabled, allows remote attackers to bypass authentication and send spam e-mail via a message with (1) a base64-encoded username that begins with a valid shortname, or (2) a username that matches a valid password, as demonstrated using (a) SMTP and qmail, and (b) Courier IMAP and POP3. | 2 | 5.8 | Medium | 2017-01-03 | 2009-09-28 | View |
Page 1343 of 17672, showing 5 records out of 88360 total, starting on record 6711, ending on 6715