NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
6467  CVE-2008-6736  Flat Calendar 1.1 does not properly restrict access to administrative functions, which allows remote attackers to (1) add new events via calAdd.php, as reachable from admin/add.php, or (2) delete events via admin/deleteEvent.php. NOTE: this is only a vulnerability when the administrator does not follow recommendations in the product"s security documentation.    6.4  Medium  2017-01-03  2009-04-22  View
6723  CVE-2008-6992  GreenSQL Firewall (greensql-fw), possibly before 0.9.2 or 0.9.4, allows remote attackers to bypass the SQL injection protection mechanism via a WHERE clause containing an expression such as "x=y=z", which is successfully parsed by MySQL.    7.5  High  2017-01-03  2009-08-19  View
6979  CVE-2008-7248  Ruby on Rails 2.1 before 2.1.3 and 2.2.x before 2.2.2 does not verify tokens for requests with certain content types, which allows remote attackers to bypass cross-site request forgery (CSRF) protection for requests to applications that rely on this protection, as demonstrated using text/plain.    6.8  Medium  2017-01-03  2012-07-06  View
73283  CVE-2003-0136  psbanner in the LPRng package allows local users to overwrite arbitrary files via a symbolic link attack on the /tmp/before file.    2.1  Low  2017-01-03  2008-09-10  View
73539  CVE-2003-0409  Buffer overflow in BRS WebWeaver 1.04 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP (1) POST or (2) HEAD request.    10  High  2017-01-03  2016-10-17  View

Page 2120 of 17672, showing 5 records out of 88360 total, starting on record 10596, ending on 10600

Actions