NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
1802 | CVE-2008-1862 | ExBB Italia 0.22 and earlier only checks GET requests that use the QUERY_STRING for certain path manipulations, which allows remote attackers to bypass this check via (1) POST or (2) COOKIE variables, a different vector than CVE-2006-4488. NOTE: this can be leveraged to conduct PHP remote file inclusion attacks via a URL in the (a) new_exbb[home_path] or (b) exbb[home_path] parameter to modules/threadstop/threadstop.php. | 2 | 6.8 | Medium | 2017-01-03 | 2008-09-05 | View | |
67850 | CVE-2005-2146 | SSH Tectia Server 4.3.1 and earlier, and SSH Secure Shell for Windows Servers, uses insecure permissions when generating the Secure Shell host identification key, which allows local users to access the key and spoof the server. | 2 | 4.6 | Medium | 2017-01-03 | 2008-09-05 | View | |
68362 | CVE-2005-2673 | SQL injection vulnerability in modcp.php in WoltLab Burning Board 2.2.2 and 2.3.3 allows remote authenticated attackers to execute arbitrary SQL commands via the (1) x or (2) y parameters. | 2 | 7.5 | High | 2017-01-03 | 2008-09-05 | View | |
69898 | CVE-2005-4300 | Format string vulnerability in the lire_pop function in pop.c in libremail 1.1.0 and earlier, with compiled with the debug option, allows remote attackers to execute arbitrary code via a crafted e-mail or POP server response. | 2 | 7.5 | High | 2017-01-03 | 2008-09-05 | View | |
70410 | CVE-2005-4821 | Multiple SQL injection vulnerabilities in Land Down Under (LDU) v801 and earlier allow remote attackers to execute arbitrary SQL commands via parameters including (1) the m parameter in auth.php, (2) the f parameter in events.php, or (3) the e parameter in plug.php. | 2 | 7.5 | High | 2017-01-03 | 2008-09-05 | View |
Page 91 of 17672, showing 5 records out of 88360 total, starting on record 451, ending on 455