NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
5604  CVE-2008-5873  Yerba SACphp 6.3 and earlier allows remote attackers to bypass authentication and gain administrative access via a galleta[sesion] cookie that has a value beginning with 1:1: followed by a username.    7.5  High  2017-01-03  2009-01-29  View
3813  CVE-2008-3951  SQL injection vulnerability in view_ann.php in Vastal I-Tech Agent Zone (aka The Real Estate Script) allows remote attackers to execute arbitrary SQL commands via the ann_id parameter.    7.5  High  2017-01-03  2009-01-29  View
5349  CVE-2008-5600  Merlix Teamworx Server stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for teamworx.mdb.    Medium  2017-01-03  2009-01-29  View
47589  CVE-2009-0255  The System extension Install tool in TYPO3 4.0.0 through 4.0.9, 4.1.0 through 4.1.7, and 4.2.0 through 4.2.3 creates the encryption key with an insufficiently random seed, which makes it easier for attackers to crack the key.    Medium  2017-01-07  2009-01-29  View
2022  CVE-2008-2087  SQL injection vulnerability in search_result.php in Softbiz Web Host Directory Script, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the host_id parameter, a different vector than CVE-2005-3817.    6.8  Medium  2017-01-03  2009-01-29  View

Page 2697 of 17672, showing 5 records out of 88360 total, starting on record 13481, ending on 13485

Actions