NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
2386 | CVE-2008-2478 | ** DISPUTED ** scripts/wwwacct in cPanel 11.18.6 STABLE and earlier and 11.23.1 CURRENT and earlier allows remote authenticated users with reseller privileges to execute arbitrary code via shell metacharacters in the Email address field (aka Email text box). NOTE: the vendor disputes this, stating "I"m unable to reproduce such an issue on multiple servers running different versions of cPanel." | 2 | 8.5 | High | 2017-01-03 | 2008-09-05 | View | |
2387 | CVE-2008-2479 | Multiple SQL injection vulnerabilities in phpFix 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) kind parameter to fix/browse.php and the (2) account parameter to auth/00_pass.php. | 2 | 6.8 | Medium | 2017-01-03 | 2008-09-10 | View | |
2388 | CVE-2008-2480 | PHP remote file inclusion vulnerability in plus.php in plusPHP Short URL Multi-User Script 1.6 allows remote attackers to execute arbitrary PHP code via a URL in the _pages_dir parameter. | 2 | 10 | High | 2017-01-03 | 2011-03-07 | View | |
2389 | CVE-2008-2481 | PHP remote file inclusion vulnerability in authentication/phpbb3/phpbb3.functions.php in phpRaider 1.0.7 and 1.0.7a, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the pConfig_auth[phpbb_path] parameter. | 2 | 10 | High | 2017-01-03 | 2011-03-07 | View | |
2390 | CVE-2008-2482 | Directory traversal vulnerability in install_mod.php in insanevisions OneCMS 2.5 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the load parameter in a go action. | 2 | 7.5 | High | 2017-01-03 | 2011-03-07 | View |
Page 478 of 17672, showing 5 records out of 88360 total, starting on record 2386, ending on 2390