NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
3530 | CVE-2008-3662 | Gallery before 1.5.9, and 2.x before 2.2.6, does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie. | 2 | 5 | Medium | 2017-01-03 | 2009-02-06 | View | |
69066 | CVE-2005-3404 | Multiple PHP file inclusion vulnerabilities in ATutor 1.4.1 through 1.5.1-pl1 allow remote attackers to include arbitrary files via the section parameter followed by a null byte (%00) in (1) body_header.inc.php and (2) print.php. | 2 | 7.5 | High | 2017-01-03 | 2016-10-17 | View | |
3786 | CVE-2008-3924 | The "Make a backup" functionality in Content Management Made Easy (CMME) 1.12 stores sensitive information under the web root with insufficient access control, which allows remote attackers to discover (1) account names and (2) password hashes via a direct request for (a) backup/cmme_data.zip or (b) backup/cmme_cmme.zip. NOTE: it was later reported that vector a also affects CMME 1.19. | 2 | 4.3 | Medium | 2017-01-03 | 2009-02-17 | View | |
4042 | CVE-2008-4186 | SQL injection vulnerability in index.php in webCMS Portal Edition allows remote attackers to execute arbitrary SQL commands via the id_doc parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | 2 | 7.5 | High | 2017-01-03 | 2008-10-23 | View | |
69578 | CVE-2005-3940 | SQL injection vulnerability in ringmaker.php in Orca Ringmaker 2.3c and earlier allows remote attackers to execute arbitrary SQL commands via the start parameter. | 2 | 7.5 | High | 2017-01-03 | 2011-03-07 | View |
Page 15694 of 17672, showing 5 records out of 88360 total, starting on record 78466, ending on 78470