NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
5321  CVE-2008-5572  Professional Download Assistant 0.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for database/downloads.mdb.    Medium  2017-01-03  2009-05-14  View
5322  CVE-2008-5573  SQL injection vulnerability in the login feature in Poll Pro 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) Password and (2) username parameters.    7.5  High  2017-01-03  2009-03-18  View
5323  CVE-2008-5574  SQL injection vulnerability in member.php in Webmaster Marketplace allows remote attackers to execute arbitrary SQL commands via the u parameter.    7.5  High  2017-01-03  2010-06-15  View
5324  CVE-2008-5575  Session fixation vulnerability in Pro Clan Manager 0.4.2 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.    7.5  High  2017-01-03  2009-04-01  View
5325  CVE-2008-5576  admin/forums.php in sCssBoard 1.0, 1.1, 1.11, and 1.12 allows remote attackers to bypass authentication and gain administrative access via a large value of the current_user[users_level] parameter.    7.5  High  2017-01-03  2009-01-29  View

Page 1065 of 17672, showing 5 records out of 88360 total, starting on record 5321, ending on 5325

Actions