NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
5910 | CVE-2008-6179 | SQL injection vulnerability in sug_cat.php in IndexScript 3.0 allows remote attackers to execute arbitrary SQL commands via the parent_id parameter, a different vector than CVE-2007-4069. | 2 | 7.5 | High | 2017-01-03 | 2009-02-20 | View | |
71446 | CVE-2004-1054 | Untrusted execution path vulnerability in invscout in IBM AIX 5.1.0, 5.2.0, and 5.3.0 allows local users to gain privileges by modifying the PATH environment variable to point to a malicious "uname" program, which is executed from lsvpd after lsvpd has been invoked by invscout. | 2 | 7.2 | High | 2017-07-18 | 2017-07-10 | View | |
6166 | CVE-2008-6435 | Multiple cross-site scripting (XSS) vulnerabilities in phpSQLiteCMS 1 RC2 allow remote attackers to inject arbitrary web script or HTML via the (1) lang[home], (2) lang[admin_menu], and (3) lang[admin_menu_page_overview] parameters to cms/includes/header.inc.php; and the (4) lang[login_username] and (5) lang[login_password] parameters to cms/includes/login.inc.php. | 2 | 4.3 | Medium | 2017-01-03 | 2009-03-09 | View | |
71702 | CVE-2004-1322 | Cisco Unity 2.x, 3.x, and 4.x, when integrated with Microsoft Exchange, has several hard coded usernames and passwords, which allows remote attackers to gain unauthorized access and change configuration settings or read outgoing or incoming e-mail messages. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View | |
6422 | CVE-2008-6691 | SQL injection vulnerability in Diocese of Portsmouth Calendar Today (pd_calendar_today) extension 0.0.3 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unknown vectors. | 2 | 7.5 | High | 2017-01-03 | 2009-04-25 | View |
Page 1854 of 17672, showing 5 records out of 88360 total, starting on record 9266, ending on 9270