NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
906  CVE-2008-0936  SQL injection vulnerability in index.php in the Prayer List (prayerlist) 1.04 module for XOOPS allows remote attackers to execute arbitrary SQL commands via the cid parameter in a view action.    7.5  High  2017-01-03  2008-09-05  View
907  CVE-2008-0937  SQL injection vulnerability in index.php in the Tiny Event (tinyevent) 1.01 module for XOOPS allows remote attackers to execute arbitrary SQL commands via the id parameter in a print action, a different vector than CVE-2007-1811.    6.8  Medium  2017-01-03  2008-09-05  View
908  CVE-2008-0938  Unspecified vulnerability in the dynamic tracing framework (DTrace) in Sun Solaris 10 allows local users with PRIV_DTRACE_USER or PRIV_DTRACE_PROC privileges to obtain sensitive kernel information via unspecified vectors, a different vulnerability than CVE-2007-4126.    4.7  Medium  2017-01-03  2011-03-07  View
909  CVE-2008-0939  Multiple SQL injection vulnerabilities in wppa.php in the WP Photo Album (WPPA) before 1.1 plugin for WordPress allow remote attackers to execute arbitrary SQL commands via (1) the photo parameter to index.php, used by the wppa_photo_name function; or (2) the album parameter to index.php, used by the wppa_album_name function. NOTE: some of these details are obtained from third party information.    7.5  High  2017-01-03  2011-03-07  View
910  CVE-2008-0940  Cross-site scripting (XSS) vulnerability in Plain Black WebGUI before 7.4.24 allows remote attackers to inject arbitrary web script or HTML when creating a username, a different vulnerability than CVE-2007-0407.    4.3  Medium  2017-01-03  2008-09-05  View

Page 182 of 17672, showing 5 records out of 88360 total, starting on record 906, ending on 910

Actions