NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 36565 | CVE-2013-0209 | lib/MT/Upgrade.pm in mt-upgrade.cgi in Movable Type 4.2x and 4.3x through 4.38 does not require authentication for requests to database-migration functions, which allows remote attackers to conduct eval injection and SQL injection attacks via crafted parameters, as demonstrated by an eval injection attack against the core_drop_meta_for_table function, leading to execution of arbitrary Perl code. | 2 | 7.5 | High | 2017-01-18 | 2013-01-29 | View | |
| 37589 | CVE-2013-1362 | Incomplete blacklist vulnerability in nrpc.c in Nagios Remote Plug-In Executor (NRPE) before 2.14 might allow remote attackers to execute arbitrary shell commands via "$()" shell metacharacters, which are processed by bash. | 2 | 7.5 | High | 2017-01-18 | 2013-12-13 | View | |
| 40149 | CVE-2013-4557 | The Security Screen (_core_/securite/ecran_securite.php) before 1.1.8 for SPIP, as used in SPIP 3.0.x before 3.0.12, allows remote attackers to execute arbitrary PHP via the connect parameter. | 2 | 7.5 | High | 2017-01-18 | 2016-12-07 | View | |
| 42965 | CVE-2012-0912 | SQL injection vulnerability in Stoneware webNetwork before 6.0.8.0 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | 2 | 7.5 | High | 2017-01-19 | 2012-01-24 | View | |
| 43221 | CVE-2012-1218 | Multiple SQL injection vulnerabilities in freelancerKit 2.35 allow remote attackers to execute arbitrary SQL commands via unspecified vectors to the (1) notes and (2) tickets components. | 2 | 7.5 | High | 2017-01-19 | 2012-02-24 | View |
Page 15229 of 17672, showing 5 records out of 88360 total, starting on record 76141, ending on 76145