NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 5604 | CVE-2008-5873 | Yerba SACphp 6.3 and earlier allows remote attackers to bypass authentication and gain administrative access via a galleta[sesion] cookie that has a value beginning with 1:1: followed by a username. | 2 | 7.5 | High | 2017-01-03 | 2009-01-29 | View | |
| 3813 | CVE-2008-3951 | SQL injection vulnerability in view_ann.php in Vastal I-Tech Agent Zone (aka The Real Estate Script) allows remote attackers to execute arbitrary SQL commands via the ann_id parameter. | 2 | 7.5 | High | 2017-01-03 | 2009-01-29 | View | |
| 5349 | CVE-2008-5600 | Merlix Teamworx Server stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for teamworx.mdb. | 2 | 5 | Medium | 2017-01-03 | 2009-01-29 | View | |
| 47589 | CVE-2009-0255 | The System extension Install tool in TYPO3 4.0.0 through 4.0.9, 4.1.0 through 4.1.7, and 4.2.0 through 4.2.3 creates the encryption key with an insufficiently random seed, which makes it easier for attackers to crack the key. | 2 | 5 | Medium | 2017-01-07 | 2009-01-29 | View | |
| 2022 | CVE-2008-2087 | SQL injection vulnerability in search_result.php in Softbiz Web Host Directory Script, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the host_id parameter, a different vector than CVE-2005-3817. | 2 | 6.8 | Medium | 2017-01-03 | 2009-01-29 | View |
Page 2697 of 17672, showing 5 records out of 88360 total, starting on record 13481, ending on 13485