NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
62330  CVE-2006-3662  ** DISPUTED ** SQL injection vulnerability in index.php in ATutor 1.5.3 allows remote attackers to execute arbitrary SQL commands via the fid parameter. NOTE: this issue has been disputed by the vendor, who states "The mentioned SQL injection vulnerability is not possible." However, the relevant source code suggests that this issue may be legitimate, and the parameter is cleansed in 1.5.3.1.    7.5  High  2016-12-20  2008-09-05  View
63354  CVE-2006-4727  Cross-site scripting (XSS) vulnerability in emfadmin/statusView.do in Tumbleweed EMF Administration Module 6.2.2 Build 4123, and possibly other versions before 6.3.2, allows remote attackers to inject arbitrary web script or HTML via the (1) lineId and (2) sort parameters.    4.3  Medium  2016-12-20  2008-09-05  View
123  CVE-2008-0133  Multiple SQL injection vulnerabilities in Tribisur 2.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to cat_main.php and the (2) cat parameter to forum.php in a liste action.    7.5  High  2017-01-03  2008-09-05  View
891  CVE-2008-0921  SQL injection vulnerability in news.php in beContent 0.3.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.    7.5  High  2017-01-03  2008-09-05  View
66427  CVE-2005-0676  index.php in Zorum 3.5 allows remote attackers to trigger an SQL error, and possibly inject arbitrary SQL commands, via the search capability.    7.5  High  2017-01-03  2008-09-05  View

Page 16793 of 17672, showing 5 records out of 88360 total, starting on record 83961, ending on 83965

Actions