NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 49040 | CVE-2009-1771 | index.php in Flyspeck CMS 6.8 does not require administrative authentication for the updateExistingContent action, which allows remote attackers to create or modify admin accounts via the (1) users[fullname], (2) users[email], (3) users[role_id], (4) users[username], and (5) users[password] parameters. | 2 | 7.5 | High | 2017-01-07 | 2009-06-09 | View | |
| 51600 | CVE-2009-4477 | SQL injection vulnerability in page.html in Xstate Real Estate 1.0 allows remote attackers to execute arbitrary SQL commands via the pid parameter. | 2 | 7.5 | High | 2017-01-07 | 2010-01-04 | View | |
| 54160 | CVE-2007-1990 | PHP remote file inclusion vulnerability in games.php in Sam Crew MyBlog, possibly 1.0 through 1.6, allows remote attackers to execute arbitrary PHP code via a URL in the id parameter, a different vector than CVE-2007-1968. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | 2 | 7.5 | High | 2017-01-07 | 2011-03-07 | View | |
| 55952 | CVE-2007-3808 | SQL injection vulnerability in includes/search.php in paFileDB 3.6 allows remote attackers to execute arbitrary SQL commands via the categories[] parameter in a search action to index.php, a different vector than CVE-2005-2000. | 2 | 7.5 | High | 2017-01-07 | 2012-11-05 | View | |
| 56464 | CVE-2007-4339 | Multiple PHP remote file inclusion vulnerabilities in PHPCentral Poll Script 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the _SERVER[DOCUMENT_ROOT] parameter in (1) poll.php and (2) pollarchive.php. NOTE: a reliable third party states that this issue is resultant from a variable extraction error in functions.php. | 2 | 7.5 | High | 2017-01-07 | 2011-09-08 | View |
Page 14440 of 17672, showing 5 records out of 88360 total, starting on record 72196, ending on 72200