NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
3178  CVE-2008-3297  Multiple SQL injection vulnerabilities in SocialEngine (SE) before 2.83 allow remote attackers to execute arbitrary SQL commands via (1) an se_user cookie to include/class_user.php or (2) an se_admin cookie to include/class_admin.php.    7.5  High  2017-01-03  2009-01-29  View
4458  CVE-2008-4644  hits.php in myWebland myStats allows remote attackers to bypass IP address restrictions via a modified X-Forwarded-For HTTP header.    7.5  High  2017-01-03  2009-01-29  View
5482  CVE-2008-5742  Multiple open redirect vulnerabilities in AIST NetCat 3.12 and earlier allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via (1) the redirect parameter in a logoff action to modules/auth/index.php or (2) the url parameter to modules/linkmanager/redirect.php. NOTE: this was reported within an "HTTP Response Splitting" section in the original disclosure.    Medium  2017-01-03  2009-01-29  View
2923  CVE-2008-3033  RSS-aggregator 1.0 does not require administrative authentication for the admin/fonctions/ directory, which allows remote attackers to access admin functions and have unspecified other impact, as demonstrated by (1) an IdFlux request to supprimer_flux.php and (2) a TpsRafraich request to modifier_tps_rafraich.php.    9.3  High  2017-01-03  2009-01-29  View
3179  CVE-2008-3298  SocialEngine (SE) before 2.83 grants certain write privileges for templates, which allows remote authenticated administrators to execute arbitrary PHP code.    Medium  2017-01-03  2009-01-29  View

Page 15010 of 17672, showing 5 records out of 88360 total, starting on record 75046, ending on 75050

Actions