NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
5586  CVE-2008-5855  myPHPscripts Login Session 2.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to discover usernames, e-mail addresses, and password hashes via a direct request for users.txt.    Medium  2017-01-03  2009-01-29  View
5587  CVE-2008-5856  Directory traversal vulnerability in scripts/export.php in ClaSS before 0.8.61 allows remote attackers to read arbitrary files via directory traversal sequences in the ftype parameter.    Medium  2017-01-03  2009-07-10  View
5588  CVE-2008-5857  The DropDocuments plugin in KnowledgeTree before 3.5.4a allows remote authenticated users to gain administrative privileges via a certain sequence of "browse documents" and dashboard requests.    6.5  Medium  2017-01-03  2009-08-15  View
5589  CVE-2008-5858  Multiple cross-site scripting (XSS) vulnerabilities in KnowledgeTree before 3.5.4a allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different issue than CVE-2007-4281.    4.3  Medium  2017-01-03  2009-08-19  View
5590  CVE-2008-5859  SQL injection vulnerability in index.php in Constructr CMS 3.02.5 and earlier, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the show_page parameter.    5.1  Medium  2017-01-03  2009-01-29  View

Page 1118 of 17672, showing 5 records out of 88360 total, starting on record 5586, ending on 5590

Actions