NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
5616  CVE-2008-5885  The Net Guys ASPired2Quote stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing usernames and passwords via a direct request for admin/quote.mdb. NOTE: some of these details are obtained from third party information.    Medium  2017-01-03  2009-01-29  View
5617  CVE-2008-5886  TAKempis Discussion Web 4.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing a password via a direct request for _private/discussion.mdb. NOTE: some of these details are obtained from third party information.    Medium  2017-01-03  2009-01-29  View
5618  CVE-2008-5887  phplist before 2.10.8 allows remote attackers to include files via unknown vectors, related to a "local file include vulnerability."    Medium  2017-01-03  2011-05-03  View
5619  CVE-2008-5888  Multiple SQL injection vulnerabilities in Click&Rank allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) hitcounter.asp, (2) user_delete.asp, and (3) user_update.asp; (4) the userid parameter to admin_login.asp (aka the USERNAME field in admin.asp); and (5) the PassWord parameter to admin_login.asp (aka the PASSWORD field in admin.asp). NOTE: some of these details are obtained from third party information.    7.5  High  2017-01-03  2009-01-29  View
5620  CVE-2008-5889  Cross-site scripting (XSS) vulnerability in user.asp in Click&Rank allows remote attackers to inject arbitrary web script or HTML via the action parameter.    4.3  Medium  2017-01-03  2009-01-12  View

Page 1124 of 17672, showing 5 records out of 88360 total, starting on record 5616, ending on 5620

Actions