NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
6218  CVE-2008-6487  Multiple SQL injection vulnerabilities in login.asp in Digiappz DigiAffiliate 1.4 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) admin and (2) password fields.    7.5  High  2017-01-03  2009-08-12  View
6474  CVE-2008-6743  RSMScript 1.21 allows remote attackers to bypass authentication and gain administrative privileges by setting the verified cookie to an arbitrary value and performing a direct request to (1) delete.php, (2) edit-submit.php, (3) edit.php, (4) submit.php, and (5) update.php, which bypasses the security check that is performed by verify.php.    7.5  High  2017-01-03  2009-04-23  View
6730  CVE-2008-6999  phpAuction 3.2, and possibly 3.3.0 GPL Basic edition, allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function.    Medium  2017-01-03  2009-08-19  View
6986  CVE-2008-7255  login_screen.tcl in aMSN (aka Alvaro"s Messenger) before 0.97.1 saves a password after logout, which allows physically proximate attackers to hijack a session by visiting an unattended workstation.    4.6  Medium  2017-01-03  2010-06-03  View
73290  CVE-2003-0143  The pop_msg function in qpopper 4.0.x before 4.0.5fc2 does not null terminate a message buffer after a call to Qvsnprintf, which could allow authenticated users to execute arbitrary code via a buffer overflow in a mdef command with a long macro name.    10  High  2017-01-03  2016-10-17  View

Page 2185 of 17672, showing 5 records out of 88360 total, starting on record 10921, ending on 10925

Actions