NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
1806 | CVE-2008-1866 | admin/modif_config.php in Blog Pixel Motion (aka PixelMotion) does not require admin authentication, which allows remote authenticated users to upload arbitrary PHP scripts in a ZIP archive, which is written to templateZip/ and then automatically extracted under templates/ for execution via a direct request. | 2 | 9 | High | 2017-01-03 | 2011-03-07 | View | |
1807 | CVE-2008-1867 | SQL injection vulnerability in Blog Pixel Motion (aka Blog PixelMotion) allows remote attackers to execute arbitrary SQL commands via the categorie parameter to index.php, possibly related to include/requetesIndex.php. | 2 | 7.5 | High | 2017-01-03 | 2011-03-07 | View | |
1808 | CVE-2008-1868 | admin/sauvBase.php in Blog Pixel Motion (aka Blog PixelMotion) does not require authentication, which allows remote attackers to trigger a database backup dump, and obtain the resulting blogPM.sql file that contains sensitive information. | 2 | 7.5 | High | 2017-01-03 | 2011-03-07 | View | |
1809 | CVE-2008-1869 | SQL injection vulnerability in Site Sift Listings allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php. NOTE: this issue might be site-specific. | 2 | 7.5 | High | 2017-01-03 | 2012-10-30 | View | |
1810 | CVE-2008-1870 | SQL injection vulnerability in getdata.php in PIGMy-SQL 1.4.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | 2 | 7.5 | High | 2017-01-03 | 2011-03-07 | View |
Page 362 of 17672, showing 5 records out of 88360 total, starting on record 1806, ending on 1810