NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
4406 | CVE-2008-4590 | Multiple SQL injection vulnerabilities in Stash 1.0.3 allow remote attackers to execute arbitrary SQL commands via (1) the username parameter to admin/login.php and (2) the post parameter to admin/news.php. | 2 | 7.5 | High | 2017-01-03 | 2009-01-29 | View | |
4407 | CVE-2008-4591 | Multiple cross-site scripting (XSS) vulnerabilities in admin/include/isadmin.inc.php in PhpWebGallery 1.3.4 allow remote attackers to inject arbitrary web script or HTML via the (1) lang[access_forbiden] and (2) lang[ident_title] parameters. | 2 | 4.3 | Medium | 2017-01-03 | 2009-08-19 | View | |
4408 | CVE-2008-4592 | Directory traversal vulnerability in index.php in Sports Clubs Web Panel 0.0.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the p parameter. | 2 | 10 | High | 2017-01-03 | 2011-03-07 | View | |
4409 | CVE-2008-4593 | Apple iPhone 2.1 with firmware 5F136, when Require Passcode is enabled and Show SMS Preview is disabled, allows physically proximate attackers to obtain sensitive information by performing an Emergency Call tap and then reading SMS messages on the device screen, aka Apple bug number 6267416. | 2 | 1.2 | Low | 2017-01-03 | 2009-07-22 | View | |
4410 | CVE-2008-4594 | Unspecified vulnerability in the SNMPv3 component in Linksys WAP4400N firmware 1.2.14 on the Marvell Semiconductor 88W8361P-BEM1 chipset has unknown impact and attack vectors, probably remote. | 2 | 10 | High | 2017-01-03 | 2012-10-31 | View |
Page 882 of 17672, showing 5 records out of 88360 total, starting on record 4406, ending on 4410