NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
5604  CVE-2008-5873  Yerba SACphp 6.3 and earlier allows remote attackers to bypass authentication and gain administrative access via a galleta[sesion] cookie that has a value beginning with 1:1: followed by a username.    7.5  High  2017-01-03  2009-01-29  View
72164  CVE-2004-1785  SQL injection vulnerability in calendar.php for Invision Power Board 1.3 allows remote attackers to execute arbitrary SQL commands via the m parameter, which sets the $this->chosen_month variable.    7.5  High  2016-12-20  2008-09-05  View
6884  CVE-2008-7153  SQL injection vulnerability in the autoDetectRegion function in doceboCore/lib/lib.regset.php in Docebo 3.5.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the Accept-Language HTTP header. NOTE: this can be leveraged to execute arbitrary PHP code using the INTO DUMPFILE command.    7.5  High  2017-01-03  2009-09-02  View
72676  CVE-2004-2299  Buffer overflow in Omnicron OmniHTTPd 3.0a and earlier allows remote attackers to execute arbitrary code via an HTTP GET request with a long Range header.    7.5  High  2017-07-18  2017-07-10  View
73444  CVE-2003-0309  Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to bypass security zone restrictions and execute arbitrary programs via a web document with a large number of duplicate file:// or other requests that point to the program and open multiple file download dialogs, which eventually cause Internet Explorer to execute the program, as demonstrated using a large number of FRAME or IFRAME tags, aka the File Download Dialog Vulnerability.    7.5  High  2017-07-18  2017-07-10  View

Page 15406 of 17672, showing 5 records out of 88360 total, starting on record 77026, ending on 77030

Actions