NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 660 | CVE-2008-0687 | Cross-site scripting (XSS) vulnerability in siteadmin/editor_files/includes/load_message.php in the Youtube Clone Script allows remote attackers to inject arbitrary web script or HTML via the lang[please_wait] parameter. | 2 | 7.5 | High | 2017-01-03 | 2008-12-20 | View | |
| 4348 | CVE-2008-4525 | SQL injection vulnerability in index.php in AmpJuke 0.7.5 allows remote attackers to execute arbitrary SQL commands via the special parameter in a performerid action. | 2 | 7.5 | High | 2017-01-03 | 2008-12-20 | View | |
| 4131 | CVE-2008-4303 | Multiple SQL injection vulnerabilities in phpCollab 2.5 rc3, 2.4, and earlier allow remote attackers to execute arbitrary SQL commands via the loginForm parameter to general/login.php, and unspecified other vectors. | 2 | 6.8 | Medium | 2017-01-03 | 2008-12-23 | View | |
| 4132 | CVE-2008-4304 | general/login.php in phpCollab 2.5 rc3 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in unspecified input related to the SSL_CLIENT_CERT environment variable. NOTE: in some environments, SSL_CLIENT_CERT always has a base64-encoded string value, which may impose constraints on injection for typical shells. | 2 | 10 | High | 2017-01-03 | 2008-12-23 | View | |
| 4133 | CVE-2008-4305 | Static code injection vulnerability in installation/setup.php in phpCollab 2.5 rc3 and earlier allows remote authenticated administrators to inject arbitrary PHP code into include/settings.php via the URI. | 2 | 9 | High | 2017-01-03 | 2008-12-23 | View |
Page 2566 of 17672, showing 5 records out of 88360 total, starting on record 12826, ending on 12830