NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
36565  CVE-2013-0209  lib/MT/Upgrade.pm in mt-upgrade.cgi in Movable Type 4.2x and 4.3x through 4.38 does not require authentication for requests to database-migration functions, which allows remote attackers to conduct eval injection and SQL injection attacks via crafted parameters, as demonstrated by an eval injection attack against the core_drop_meta_for_table function, leading to execution of arbitrary Perl code.    7.5  High  2017-01-18  2013-01-29  View
37589  CVE-2013-1362  Incomplete blacklist vulnerability in nrpc.c in Nagios Remote Plug-In Executor (NRPE) before 2.14 might allow remote attackers to execute arbitrary shell commands via "$()" shell metacharacters, which are processed by bash.    7.5  High  2017-01-18  2013-12-13  View
40149  CVE-2013-4557  The Security Screen (_core_/securite/ecran_securite.php) before 1.1.8 for SPIP, as used in SPIP 3.0.x before 3.0.12, allows remote attackers to execute arbitrary PHP via the connect parameter.    7.5  High  2017-01-18  2016-12-07  View
42965  CVE-2012-0912  SQL injection vulnerability in Stoneware webNetwork before 6.0.8.0 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.    7.5  High  2017-01-19  2012-01-24  View
43221  CVE-2012-1218  Multiple SQL injection vulnerabilities in freelancerKit 2.35 allow remote attackers to execute arbitrary SQL commands via unspecified vectors to the (1) notes and (2) tickets components.    7.5  High  2017-01-19  2012-02-24  View

Page 15229 of 17672, showing 5 records out of 88360 total, starting on record 76141, ending on 76145

Actions