NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
3080 | CVE-2008-3197 | Cross-site request forgery (CSRF) vulnerability in phpMyAdmin before 2.11.7.1 allows remote attackers to perform unauthorized actions via a link or IMG tag to (1) the db parameter in the "Creating a Database" functionality (db_create.php), and (2) the convcharset and collation_connection parameters related to an unspecified program that modifies the connection character set. | 2 | 3.5 | Low | 2017-01-03 | 2012-11-26 | View | |
3079 | CVE-2008-3196 | skeleton.c in yacc does not properly handle reduction of a rule with an empty right hand side, which allows context-dependent attackers to cause an out-of-bounds stack access when the yacc stack pointer points to the end of the stack. | 2 | 7.8 | High | 2017-01-03 | 2012-11-26 | View | |
3078 | CVE-2008-3195 | Directory traversal vulnerability in bin/configure in TWiki before 4.2.3, when a certain step in the installation guide is skipped, allows remote attackers to read arbitrary files via a query string containing a .. (dot dot) in the image variable, and execute arbitrary files via unspecified vectors. | 2 | 6.8 | Medium | 2017-01-03 | 2011-03-07 | View | |
3077 | CVE-2008-3194 | Multiple directory traversal vulnerabilities in data/inc/themes/predefined_variables.php in pluck 4.5.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) langpref, (2) file, (3) blogpost, or (4) cat parameter. | 2 | 6.8 | Medium | 2017-01-03 | 2011-03-07 | View | |
3076 | CVE-2008-3193 | SQL injection vulnerability in jSite 1.0 OE allows remote attackers to execute arbitrary SQL commands via the page parameter to the default URI. | 2 | 7.5 | High | 2017-01-03 | 2009-01-29 | View |
Page 17057 of 17672, showing 5 records out of 88360 total, starting on record 85281, ending on 85285