NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
67612 | CVE-2005-1894 | Direct code injection vulnerability in FlatNuke 2.5.3 allows remote attackers to execute arbitrary PHP code by placing the code into the Referer header of an HTTP request, which causes the code to be injected into referer.php, which can then be accessed by the attacker. | 2 | 7.5 | High | 2017-01-03 | 2011-03-07 | View | |
2332 | CVE-2008-2416 | SQL injection vulnerability in index.php in FicHive 1.0 allows remote attackers to execute arbitrary SQL commands via the category parameter in a Fiction action, possibly related to sources/fiction.class.php. | 2 | 7.5 | High | 2017-01-03 | 2011-08-08 | View | |
67868 | CVE-2005-2164 | SQL injection vulnerability in Covide Groupware-CRM allows remote attackers to execute arbitrary SQL commands via unknown attack vectors. | 2 | 7.5 | High | 2017-01-03 | 2016-10-17 | View | |
2588 | CVE-2008-2690 | Multiple PHP remote file inclusion vulnerabilities in BrowserCRM 5.002.00, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the bcrm_pub_root parameter to (1) kb.php, (2) login.php, (3) index.php, (4) contact_view.php, and (5) contact.php in pub/, different vectors than CVE-2008-2689. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | 2 | 9.3 | High | 2017-01-03 | 2009-04-08 | View | |
2844 | CVE-2008-2950 | The Page destructor in Page.cc in libpoppler in Poppler 0.8.4 and earlier deletes a pageWidgets object even if it is not initialized by a Page constructor, which allows remote attackers to execute arbitrary code via a crafted PDF document. | 2 | 7.5 | High | 2017-01-03 | 2012-11-26 | View |
Page 1684 of 17672, showing 5 records out of 88360 total, starting on record 8416, ending on 8420