NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
3955 | CVE-2008-4097 | MySQL 5.0.51a allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are associated with symlinks within pathnames for subdirectories of the MySQL home data directory, which are followed when tables are created in the future. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-2079. | 2 | 4.6 | Medium | 2017-01-03 | 2012-10-30 | View | |
3954 | CVE-2008-4096 | libraries/database_interface.lib.php in phpMyAdmin before 2.11.9.1 allows remote authenticated users to execute arbitrary code via a request to server_databases.php with a sort_by parameter containing PHP sequences, which are processed by create_function. | 2 | 8.5 | High | 2017-01-03 | 2011-03-07 | View | |
3953 | CVE-2008-4095 | Multiple unspecified vulnerabilities in the Importer in Flip4Mac WMV before 2.2.1 have unknown impact and attack vectors, different vulnerabilities than CVE-2007-6713. | 2 | 10 | High | 2017-01-03 | 2011-03-07 | View | |
3952 | CVE-2008-4094 | Multiple SQL injection vulnerabilities in Ruby on Rails before 2.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) :limit and (2) :offset parameters, related to ActiveRecord, ActiveSupport, ActiveResource, ActionPack, and ActionMailer. | 2 | 7.5 | High | 2017-01-03 | 2012-07-06 | View | |
3951 | CVE-2008-4093 | SQL injection vulnerability in memberstats.php in YourOwnBux 3.1 and 3.2 beta, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the user parameter. | 2 | 6.8 | Medium | 2017-01-03 | 2009-08-20 | View |
Page 16882 of 17672, showing 5 records out of 88360 total, starting on record 84406, ending on 84410