NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
1796 | CVE-2008-1856 | plugins/maps/db_handler.php in LinPHA 1.3.3 and earlier does not require authentication for a settings action that modifies the configuration file, which allows remote attackers to conduct directory traversal attacks and execute arbitrary local files by placing directory traversal sequences into the maps_type configuration setting, and then sending a request to maps_view.php, which causes plugins/maps/map.main.class.php to use the modified configuration. | 2 | 5.1 | Medium | 2017-01-03 | 2011-03-07 | View | |
1797 | CVE-2008-1857 | Multiple directory traversal vulnerabilities in viewsource.php in Make our Life Easy (Mole) 2.1.0 allow remote attackers to read arbitrary files via directory traversal sequences in the (1) dirn and (2) fname parameters. | 2 | 6.8 | Medium | 2017-01-03 | 2011-03-07 | View | |
1798 | CVE-2008-1858 | SQL injection vulnerability in index.php in 724Networks 724CMS 4.01 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter. | 2 | 7.5 | High | 2017-01-03 | 2012-10-29 | View | |
1799 | CVE-2008-1859 | SQL injection vulnerability in events.php in iScripts SocialWare allows remote attackers to execute arbitrary SQL commands via the id parameter in a show action. | 2 | 7.5 | High | 2017-01-03 | 2012-10-30 | View | |
1800 | CVE-2008-1860 | Static code injection vulnerability in admin.php in LokiCMS 0.3.3 and earlier allows remote attackers to inject arbitrary PHP code into includes/Config.php via the default parameter. | 2 | 9.3 | High | 2017-01-03 | 2011-03-07 | View |
Page 360 of 17672, showing 5 records out of 88360 total, starting on record 1796, ending on 1800