NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 5685 | CVE-2008-5954 | SQL injection vulnerability in KTP Computer Customer Database (KTPCCD) CMS, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the lname parameter in a login action to an unspecified component. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | 2 | 6.8 | Medium | 2017-01-03 | 2009-02-10 | View | |
| 5941 | CVE-2008-6210 | SQL injection vulnerability in index.php in dream4 Koobi 4.4 and 5.4 allows remote attackers to execute arbitrary SQL commands via the img_id parameter in the gallerypic page. | 2 | 7.5 | High | 2017-01-03 | 2009-02-20 | View | |
| 6197 | CVE-2008-6466 | SQL injection vulnerability in image_gallery.php in the Akira Powered Image Gallery (image_gallery) plugin 0.9.6.2 for e107 allows remote attackers to execute arbitrary SQL commands via the image parameter in an image-detail action. | 2 | 7.5 | High | 2017-01-03 | 2009-08-07 | View | |
| 6453 | CVE-2008-6722 | Novell Access Manager 3 SP4 does not properly expire X.509 certificate sessions, which allows physically proximate attackers to obtain a logged-in session by using a victim"s web-browser process that continues to send the original and valid SSL sessionID, related to inability of Apache Tomcat to clear entries from its SSL cache. | 2 | 1.9 | Low | 2017-01-03 | 2009-04-29 | View | |
| 71989 | CVE-2004-1610 | SalesLogix 6.1 uses client-specified pathnames for writing certain files, which might allow remote authenticated users to create arbitrary files and execute code via the (1) vMME.AttachmentPath or (2) vMME.LibraryPath variables. | 2 | 7.5 | High | 2016-12-20 | 2016-10-17 | View |
Page 3195 of 17672, showing 5 records out of 88360 total, starting on record 15971, ending on 15975