NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
5586 | CVE-2008-5855 | myPHPscripts Login Session 2.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to discover usernames, e-mail addresses, and password hashes via a direct request for users.txt. | 2 | 5 | Medium | 2017-01-03 | 2009-01-29 | View | |
5587 | CVE-2008-5856 | Directory traversal vulnerability in scripts/export.php in ClaSS before 0.8.61 allows remote attackers to read arbitrary files via directory traversal sequences in the ftype parameter. | 2 | 5 | Medium | 2017-01-03 | 2009-07-10 | View | |
5588 | CVE-2008-5857 | The DropDocuments plugin in KnowledgeTree before 3.5.4a allows remote authenticated users to gain administrative privileges via a certain sequence of "browse documents" and dashboard requests. | 2 | 6.5 | Medium | 2017-01-03 | 2009-08-15 | View | |
5589 | CVE-2008-5858 | Multiple cross-site scripting (XSS) vulnerabilities in KnowledgeTree before 3.5.4a allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different issue than CVE-2007-4281. | 2 | 4.3 | Medium | 2017-01-03 | 2009-08-19 | View | |
5590 | CVE-2008-5859 | SQL injection vulnerability in index.php in Constructr CMS 3.02.5 and earlier, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the show_page parameter. | 2 | 5.1 | Medium | 2017-01-03 | 2009-01-29 | View |
Page 1118 of 17672, showing 5 records out of 88360 total, starting on record 5586, ending on 5590