NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 2428 | CVE-2008-2520 | Multiple PHP remote file inclusion vulnerabilities in BigACE 2.4, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) GLOBALS[_BIGACE][DIR][addon] parameter to (a) addon/smarty/plugins/function.captcha.php and (b) system/classes/sql/AdoDBConnection.php; and the (2) GLOBALS[_BIGACE][DIR][admin] parameter to (c) item_information.php and (d) jstree.php in system/application/util/, and (e) system/admin/plugins/menu/menuTree/plugin.php, different vectors than CVE-2006-4423. | 2 | 7.5 | High | 2017-01-03 | 2009-04-01 | View | |
| 2430 | CVE-2008-2522 | SQL injection vulnerability in members.php in Battle.net Clan Script for PHP 1.5.3 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the showmember parameter in a members action. | 2 | 6.8 | Medium | 2017-01-03 | 2009-04-01 | View | |
| 2432 | CVE-2008-2524 | BlogPHP 2.0 allows remote attackers to bypass authentication, and post (1) messages or (2) comments as an arbitrary user, via a modified blogphp_username field in a cookie. | 2 | 5 | Medium | 2017-01-03 | 2009-04-01 | View | |
| 4992 | CVE-2008-5208 | SQL injection vulnerability in sub_votepic.php in the Datsogallery (com_datsogallery) module 1.6 for Joomla! allows remote attackers to execute arbitrary SQL commands via the User-Agent HTTP header. | 2 | 7.5 | High | 2017-01-03 | 2009-04-01 | View | |
| 4993 | CVE-2008-5209 | Directory traversal vulnerability in modules/download/get_file.php in Admidio 1.4.8 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter. | 2 | 5 | Medium | 2017-01-03 | 2009-04-01 | View |
Page 2910 of 17672, showing 5 records out of 88360 total, starting on record 14546, ending on 14550