NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
906 | CVE-2008-0936 | SQL injection vulnerability in index.php in the Prayer List (prayerlist) 1.04 module for XOOPS allows remote attackers to execute arbitrary SQL commands via the cid parameter in a view action. | 2 | 7.5 | High | 2017-01-03 | 2008-09-05 | View | |
907 | CVE-2008-0937 | SQL injection vulnerability in index.php in the Tiny Event (tinyevent) 1.01 module for XOOPS allows remote attackers to execute arbitrary SQL commands via the id parameter in a print action, a different vector than CVE-2007-1811. | 2 | 6.8 | Medium | 2017-01-03 | 2008-09-05 | View | |
908 | CVE-2008-0938 | Unspecified vulnerability in the dynamic tracing framework (DTrace) in Sun Solaris 10 allows local users with PRIV_DTRACE_USER or PRIV_DTRACE_PROC privileges to obtain sensitive kernel information via unspecified vectors, a different vulnerability than CVE-2007-4126. | 2 | 4.7 | Medium | 2017-01-03 | 2011-03-07 | View | |
909 | CVE-2008-0939 | Multiple SQL injection vulnerabilities in wppa.php in the WP Photo Album (WPPA) before 1.1 plugin for WordPress allow remote attackers to execute arbitrary SQL commands via (1) the photo parameter to index.php, used by the wppa_photo_name function; or (2) the album parameter to index.php, used by the wppa_album_name function. NOTE: some of these details are obtained from third party information. | 2 | 7.5 | High | 2017-01-03 | 2011-03-07 | View | |
910 | CVE-2008-0940 | Cross-site scripting (XSS) vulnerability in Plain Black WebGUI before 7.4.24 allows remote attackers to inject arbitrary web script or HTML when creating a username, a different vulnerability than CVE-2007-0407. | 2 | 4.3 | Medium | 2017-01-03 | 2008-09-05 | View |
Page 182 of 17672, showing 5 records out of 88360 total, starting on record 906, ending on 910