NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
4413  CVE-2008-4597  Shindig-Integrator 5.x, a module for Drupal, does not properly restrict generated page access, which allows remote attackers to gain privileges via unspecified vectors.    7.5  High  2017-01-03  2009-07-22  View
4669  CVE-2008-4880  SQL injection vulnerability in prodshow.php in Maran PHP Shop allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2008-4879.    7.5  High  2017-01-03  2009-03-03  View
70205  CVE-2005-4616  SQL injection vulnerability in index.php in iSupport 1.06 allows remote attackers to execute arbitrary SQL commands via the include_file parameter.    7.5  High  2017-01-03  2008-09-20  View
5181  CVE-2008-5408  Buffer overflow in the data management protocol in Symantec Backup Exec for Windows Servers 11.0 (aka 11d) builds 6235 and 7170, 12.0 build 1364, and 12.5 build 2213 allows remote authenticated users to cause a denial of service (application crash) and possibly execute arbitrary code via unknown vectors. NOTE: this can be exploited by unauthenticated remote attackers by leveraging CVE-2008-5407.    High  2017-01-03  2011-03-07  View
5437  CVE-2008-5695  wp-admin/options.php in WordPress MU before 1.3.2, and WordPress 2.3.2 and earlier, does not properly validate requests to update an option, which allows remote authenticated users with manage_options and upload_files capabilities to execute arbitrary code by uploading a PHP script and adding this script"s pathname to active_plugins.    8.5  High  2017-01-03  2009-01-29  View

Page 1964 of 17672, showing 5 records out of 88360 total, starting on record 9816, ending on 9820

Actions