NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 5543 | CVE-2008-5803 | SQL injection vulnerability in admin/login.php in E-topbiz Online Store 1.0 allows remote attackers to execute arbitrary SQL commands via the user parameter (aka username field). NOTE: some of these details are obtained from third party information. | 2 | 7.5 | High | 2017-01-03 | 2009-02-26 | View | |
| 5549 | CVE-2008-5809 | futomi CGI Cafe Access Analyzer CGI Standard 4.0.1 and earlier and Access Analyzer CGI Professional 4.11.3 and earlier use a predictable session id, which makes it easier for remote attackers to hijack sessions, and obtain sensitive information about analysis results, via a modified id. | 2 | 5.8 | Medium | 2017-01-03 | 2009-02-26 | View | |
| 5551 | CVE-2008-5811 | SQL injection vulnerability in the PaxGallery (com_paxgallery) component 0.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the gid parameter in a table action to index.php. | 2 | 7.5 | High | 2017-01-03 | 2009-02-26 | View | |
| 5041 | CVE-2008-5263 | Multiple stack-based buffer overflows in the mt_codec::getHdrHead function in kernel/kls_hdr/fmt_codec_hdr.cpp in ksquirrel-libs 0.8.0 allow context-dependent attackers to execute arbitrary code via a crafted Radiance RGBE image (aka .hdr file). | 2 | 6.8 | Medium | 2017-01-03 | 2009-02-26 | View | |
| 56243 | CVE-2007-4112 | Multiple SQL injection vulnerabilities in Advanced Webhost Billing System (AWBS) before 2.6.0, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via unspecified vectors. NOTE: this can be leveraged for XSS attacks that "bypass AWBS"s anti-XSS input validation." | 2 | 6.8 | Medium | 2017-01-07 | 2009-02-26 | View |
Page 2797 of 17672, showing 5 records out of 88360 total, starting on record 13981, ending on 13985