NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 6467 | CVE-2008-6736 | Flat Calendar 1.1 does not properly restrict access to administrative functions, which allows remote attackers to (1) add new events via calAdd.php, as reachable from admin/add.php, or (2) delete events via admin/deleteEvent.php. NOTE: this is only a vulnerability when the administrator does not follow recommendations in the product"s security documentation. | 2 | 6.4 | Medium | 2017-01-03 | 2009-04-22 | View | |
| 6468 | CVE-2008-6737 | Crysis 1.21 and earlier allows remote attackers to obtain sensitive player information such as real IP addresses by sending a keyexchange packet without a previous join packet, which causes Crysis to send a disconnect packet that includes unrelated log information. | 2 | 7.8 | High | 2017-01-03 | 2009-04-22 | View | |
| 6469 | CVE-2008-6738 | MyShoutPro 1.2 allows remote attackers to bypass authentication and gain administrative access by setting the admin_access cookie to 1. | 2 | 7.5 | High | 2017-01-03 | 2009-04-22 | View | |
| 6470 | CVE-2008-6739 | Todd Woolums ASP Download management script 1.03 does not require authentication for setupdownload.asp, which allows remote attackers to gain administrator privileges via a direct request. | 2 | 7.5 | High | 2017-01-03 | 2009-04-22 | View | |
| 6472 | CVE-2008-6741 | SQL injection vulnerability in Load.php in Simple Machines Forum (SMF) 1.1.4 and earlier allows remote attackers to execute arbitrary SQL commands by setting the db_character_set parameter to a multibyte character set such as big5, which causes the addslashes PHP function to produce a "" (backslash) sequence that does not quote the """ (single quote) character, as demonstrated via a manlabels action to index.php. | 2 | 7.5 | High | 2017-01-03 | 2009-04-22 | View |
Page 3005 of 17672, showing 5 records out of 88360 total, starting on record 15021, ending on 15025