NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
6855 | CVE-2008-7124 | zKup CMS 2.0 through 2.3 does not require administrative authentication for admin/configuration/modifier.php, which allows remote attackers to gain administrator privileges via a direct request, as demonstrated by adding a new administrator. | 2 | 7.5 | High | 2017-01-03 | 2009-08-31 | View | |
6854 | CVE-2008-7123 | Static code injection vulnerability in admin/configuration/modifier.php in zKup CMS 2.0 through 2.3 allows remote attackers to inject arbitrary PHP code into fichiers/config.php via a null byte (%00) in the login parameter in an ajout action, which bypasses the regular expression check. | 2 | 6.8 | Medium | 2017-01-03 | 2009-08-31 | View | |
6853 | CVE-2008-7122 | Multiple insecure method vulnerabilities in an ActiveX control in (epRegPro.ocx) in Evans Programming Registry Pro allow remote attackers to read and modify sensitive registry keys via the (1) About, (2) CreateKey, (3) DeleteBranch, (4) DeleteKey, (5) DeleteValue, (6) EnumKeys, (7) EnumValues, (8) QueryType, (9) QueryValue, (10) RenameKey, and (11) SetValue methods. | 2 | 10 | High | 2017-01-03 | 2009-08-31 | View | |
6852 | CVE-2008-7121 | Cross-site scripting (XSS) vulnerability in Mr. CGI Guy Hot Links SQL-PHP 3 and earlier allows remote attackers to inject arbitrary web script or HTML via the search bar. | 2 | 4.3 | Medium | 2017-01-03 | 2009-08-28 | View | |
6851 | CVE-2008-7120 | SQL injection vulnerability in Mr. CGI Guy Hot Links SQL-PHP 3 and earlier allows remote attackers to execute arbitrary SQL commands via the news.php parameter. | 2 | 7.5 | High | 2017-01-03 | 2009-08-28 | View |
Page 16302 of 17672, showing 5 records out of 88360 total, starting on record 81506, ending on 81510