NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
6846  CVE-2008-7115  The web interface to the Belkin Wireless G router and ADSL2 modem F5D7632-4V6 with firmware 6.01.08 allows remote attackers to bypass authentication and gain administrator privileges via a direct request to (1) statusprocess.exe, (2) system_all.exe, or (3) restore.exe in cgi-bin/. NOTE: the setup_dns.exe vector is already covered by CVE-2008-1244.    10  High  2017-01-03  2009-08-28  View
6847  CVE-2008-7116  SQL injection vulnerability in the admin panel (admin/) in WeBid auction script 0.5.4 allows remote attackers to execute arbitrary SQL commands via the username.    7.5  High  2017-01-03  2009-08-28  View
6848  CVE-2008-7117  eledicss.php in WeBid auction script 0.5.4 allows remote attackers to modify arbitrary cascading style sheets (CSS) files via a certain request with the file parameter set to style.css. NOTE: this can probably be leveraged for cross-site scripting (XSS) attacks.    Medium  2017-01-03  2009-08-28  View
6849  CVE-2008-7118  WeBid auction script 0.5.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain SQL query logs via a direct request for logs/cron.log.    Medium  2017-01-03  2009-08-28  View
6850  CVE-2008-7119  SQL injection vulnerability in item.php in WeBid auction script 0.5.4 allows remote attackers to execute arbitrary SQL commands via the id parameter.    7.5  High  2017-01-03  2009-08-28  View

Page 1370 of 17672, showing 5 records out of 88360 total, starting on record 6846, ending on 6850

Actions