NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
120 | CVE-2008-0130 | SQL injection vulnerability in login_form.asp in Instant Softwares Dating Site allows remote attackers to execute arbitrary SQL commands via the Username parameter, a different vulnerability than CVE-2007-6671. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | 2 | 7.5 | High | 2017-01-03 | 2011-08-05 | View | |
119 | CVE-2008-0129 | SQL injection vulnerability in starnet/addons/slideshow_full.php in Site@School 2.3.10 and earlier allows remote attackers to execute arbitrary SQL commands via the album_name parameter. | 2 | 6.8 | Medium | 2017-01-03 | 2008-09-05 | View | |
118 | CVE-2008-0128 | The SingleSignOn Valve (org.apache.catalina.authenticator.SingleSignOn) in Apache Tomcat before 5.5.21 does not set the secure flag for the JSESSIONIDSSO cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie. | 2 | 5 | Medium | 2017-01-03 | 2011-03-07 | View | |
117 | CVE-2008-0127 | The administration interface in McAfee E-Business Server 8.5.2 and earlier allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a long initial authentication packet. | 2 | 8.8 | High | 2017-01-03 | 2011-03-07 | View | |
116 | CVE-2008-0125 | Cross-site scripting (XSS) vulnerability in phpstats.php in Michael Wagner phpstats 0.1 alpha allows remote attackers to inject arbitrary web script or HTML via the baseDir parameter. | 2 | 4.3 | Medium | 2017-01-03 | 2008-10-11 | View |
Page 17649 of 17672, showing 5 records out of 88360 total, starting on record 88241, ending on 88245