NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
5681 | CVE-2008-5950 | SQL injection vulnerability in media/media_level.asp in ASP Template Creature allows remote attackers to execute arbitrary SQL commands via the mcatid parameter. | 2 | 7.5 | High | 2017-01-03 | 2009-01-26 | View | |
5682 | CVE-2008-5951 | ASP Template Creature stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for workDB/templatemonster.mdb. | 2 | 5 | Medium | 2017-01-03 | 2009-01-26 | View | |
5683 | CVE-2008-5952 | SQL injection vulnerability in KTP Computer Customer Database (KTPCCD) CMS, when magic_quotes_gpc is disabled, allows remote authenticated users to execute arbitrary SQL commands via the tid parameter in a vtech action to the default URI. | 2 | 6 | Medium | 2017-01-03 | 2011-03-07 | View | |
5684 | CVE-2008-5953 | Directory traversal vulnerability in KTP Computer Customer Database (KTPCCD) CMS, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the p parameter to the default URI. | 2 | 7.5 | High | 2017-01-03 | 2011-03-07 | View | |
5685 | CVE-2008-5954 | SQL injection vulnerability in KTP Computer Customer Database (KTPCCD) CMS, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the lname parameter in a login action to an unspecified component. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | 2 | 6.8 | Medium | 2017-01-03 | 2009-02-10 | View |
Page 1137 of 17672, showing 5 records out of 88360 total, starting on record 5681, ending on 5685