NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 6000 | CVE-2008-6269 | Joovili 3.1.4 allows remote attackers to bypass authentication and gain privileges as other users, including the administrator, by setting the (1) session_id, session_logged_in, and session_username cookies for user privileges; (2) session_admin_id, session_admin_username, and session_admin cookies for admin privileges; and (3) session_staff_id, session_staff_username, and session_staff cookies for staff users. | 2 | 7.5 | High | 2017-01-03 | 2009-06-23 | View | |
| 6256 | CVE-2008-6525 | SQL injection vulnerability in the Admin Panel in Nice PHP FAQ Script (Knowledge base Script) allows remote attackers to execute arbitrary SQL commands via the Password parameter (aka the pass field). | 2 | 7.5 | High | 2017-01-03 | 2009-10-05 | View | |
| 6512 | CVE-2008-6781 | SQL injection vulnerability in directory.php in Sites for Scripts (SFS) Gaming Directory allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a list action. | 2 | 7.5 | High | 2017-01-03 | 2009-05-19 | View | |
| 6768 | CVE-2008-7037 | The Sidebar gadget in ITN News Gadget (aka ITN Hub Gadget) 1.06 for Windows Vista, and possibly other versions before 1.23, allows remote web servers or man-in-the-middle attackers to execute arbitrary commands via script in a short_title response. | 2 | 7.5 | High | 2017-01-03 | 2009-08-28 | View | |
| 72304 | CVE-2004-1926 | Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to inject arbitrary code via the (1) Theme, (2) Country, (3) Real Name, or (4) Displayed time zone fields in a User Profile, or the (5) Name, (6) Description, (7) URL, or (8) Country fields in a Directory/Add Site operation. | 2 | 7.5 | High | 2016-12-20 | 2016-10-17 | View |
Page 3224 of 17672, showing 5 records out of 88360 total, starting on record 16116, ending on 16120