NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
6816  CVE-2008-7085  Multiple SQL injection vulnerabilities in TheHockeyStop HockeySTATS Online 2.0 Basic and Advanced allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in the viewpage action to the default URI, probably index.php, or (2) divid parameter in the schedule action to index.php.    7.5  High  2017-01-03  2009-08-26  View
6817  CVE-2008-7086  Maian Greetings 2.1 allows remote attackers to bypass authentication and gain administrative privileges by setting the mecard_admin_cookie cookie to admin.    7.5  High  2017-01-03  2009-08-26  View
6818  CVE-2008-7087  PHP remote file inclusion vulnerability in search_wA.php in OpenPro 1.3.1 allows remote attackers to execute arbitrary PHP code via a URL in the LIBPATH parameter.    7.5  High  2017-01-03  2009-09-04  View
6819  CVE-2008-7088  Unrestricted file upload vulnerability in upload.php in PhotoPost vBGallery 2.4.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension followed by a safe extension, then accessing it via a direct request to the file in a certain path. NOTE: this may be the same vulnerability as CVE-2008-0251, but this is not clear due to lack of details from the vendor.    6.5  Medium  2017-01-03  2009-08-26  View
6820  CVE-2008-7089  Cross-site scripting (XSS) vulnerability in Pligg 9.9 and earlier allows remote attackers to inject arbitrary web script or HTML via the keyword parameter in a search action to user.php and other unspecified vectors.    4.3  Medium  2017-01-03  2009-08-26  View

Page 1364 of 17672, showing 5 records out of 88360 total, starting on record 6816, ending on 6820

Actions