NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 4004 | CVE-2008-4148 | SQL injection vulnerability in the Mailhandler module 5.x before 5.x-1.4 and 6.x before 6.x-1.4, a module for Drupal, allows remote attackers to execute arbitrary SQL commands via unspecified vectors, related to composing queries without using the Drupal database API. | 2 | 7.5 | High | 2017-01-03 | 2009-08-19 | View | |
| 69540 | CVE-2005-3902 | Cross-site scripting (XSS) vulnerability in gui/errordocs/index.php in Virtual Hosting Control System (VHCS) 2.2.0 through 2.4.6.2 allows remote attackers to inject arbitrary web script or HTML via query strings that are included in an error message, as demonstrated using a parameter containing script. | 2 | 4.3 | Medium | 2017-01-03 | 2016-10-17 | View | |
| 4260 | CVE-2008-4435 | Multiple cross-site scripting (XSS) vulnerabilities in the RMSOFT Downloads Plus (rmdp) module 1.5 and 1.7 for Xoops allow remote attackers to inject arbitrary web script or HTML via the (1) key parameter to search.php and the (2) id parameter to down.php. | 2 | 4.3 | Medium | 2017-01-03 | 2009-07-23 | View | |
| 69796 | CVE-2005-4198 | SQL injection vulnerability in index.php in Netref 3.0 allows remote attackers to execute arbitrary SQL commands via the cat parameter. NOTE: the provenance of this issue is unknown; the details were obtained solely from third party sources. | 2 | 7.5 | High | 2017-01-03 | 2011-08-05 | View | |
| 4516 | CVE-2008-4702 | Multiple directory traversal vulnerabilities in PhpWebGallery 1.3.4 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) user[language] and (2) user[template] parameters to (a) init.inc.php, and (b) the user[language] parameter to isadmin.inc.php. | 2 | 7.5 | High | 2017-01-03 | 2009-08-19 | View |
Page 15359 of 17672, showing 5 records out of 88360 total, starting on record 76791, ending on 76795