NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
4456 | CVE-2008-4642 | SQL injection vulnerability in profile.php in AstroSPACES 1.1.1 allows remote attackers to execute arbitrary SQL commands via the id parameter in a view action. | 2 | 7.5 | High | 2017-01-03 | 2009-01-29 | View | |
4457 | CVE-2008-4643 | SQL injection vulnerability in hits.php in myWebland myStats allows remote attackers to execute arbitrary SQL commands via the sortby parameter. | 2 | 7.5 | High | 2017-01-03 | 2009-01-29 | View | |
4458 | CVE-2008-4644 | hits.php in myWebland myStats allows remote attackers to bypass IP address restrictions via a modified X-Forwarded-For HTTP header. | 2 | 7.5 | High | 2017-01-03 | 2009-01-29 | View | |
4459 | CVE-2008-4645 | plugins/event_tracer/event_list.php in PhpWebGallery 1.7.2 and earlier allows remote authenticated administrators to execute arbitrary PHP code via PHP sequences in the sort parameter, which is processed by create_function. | 2 | 9 | High | 2017-01-03 | 2009-01-29 | View | |
4460 | CVE-2008-4646 | The Websense Reporter Module in Websense Enterprise 6.3.2 stores the SQL database system administrator password in plaintext in CreateDbInstall.log, which allows local users to gain privileges to the database. | 2 | 2.1 | Low | 2017-01-03 | 2011-03-07 | View |
Page 892 of 17672, showing 5 records out of 88360 total, starting on record 4456, ending on 4460