NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
49991  CVE-2009-2766  httpd.c in httpd in the management GUI in DD-WRT 24 sp1 does not require administrative authentication for programs under cgi-bin/, which allows remote attackers to change settings via HTTP requests.    7.5  High  2017-01-07  2009-08-15  View
3938  CVE-2008-4080  SQL injection vulnerability in Stash 1.0.3, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the (1) username parameter to admin/library/authenticate.php and the (2) download parameter to downloadmp3.php. NOTE: some of these details are obtained from third party information.    6.8  Medium  2017-01-03  2009-08-15  View
5236  CVE-2008-5486  SQL injection vulnerability in admin.php in TurnkeyForms Text Link Sales allows remote attackers to execute arbitrary SQL commands via the id parameter.    7.5  High  2017-01-03  2009-08-15  View
5237  CVE-2008-5487  Cross-site scripting (XSS) vulnerability in admin.php in TurnkeyForms Text Link Sales allows remote attackers to inject arbitrary web script or HTML via the id parameter.    4.3  Medium  2017-01-03  2009-08-15  View
6005  CVE-2008-6274  Multiple SQL injection vulnerabilities in index.php in FamilyProject 2.0 allow remote attackers to execute arbitrary SQL commands via (1) the logmbr parameter (aka login field) or (2) the mdpmbr parameter (aka pass or "Mot de passe" field). NOTE: some of these details are obtained from third party information.    6.8  Medium  2017-01-03  2009-08-15  View

Page 3309 of 17672, showing 5 records out of 88360 total, starting on record 16541, ending on 16545

Actions