NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
6026 | CVE-2008-6295 | Multiple cross-site scripting (XSS) vulnerabilities in Camera Life 2.6.2b8 allow remote attackers to inject arbitrary web script or HTML via the q parameter to (1) search.php and (2) rss.php; the query string after the image name in (3) photos/photo; the path parameter to (4) folder.php; page parameter and REQUEST_URI to (5) login.php; ver parameter to (6) media.php; theme parameter to (7) modules/iconset/iconset-debug.php; and the REQUEST_URI to (8) index.php. | 2 | 4.3 | Medium | 2017-01-03 | 2009-02-26 | View | |
6027 | CVE-2008-6296 | admin.php in Maran PHP Shop allows remote attackers to bypass authentication and gain administrative access by setting the user cookie to "demo." | 2 | 7.5 | High | 2017-01-03 | 2009-02-26 | View | |
6028 | CVE-2008-6297 | Cross-site scripting (XSS) vulnerability in order.php in DHCart allows remote attackers to inject arbitrary web script or HTML via the (1) domain and (2) d1 parameters. | 2 | 4.3 | Medium | 2017-01-03 | 2009-03-13 | View | |
6029 | CVE-2008-6298 | Unspecified vulnerability in sISAPILocation before 1.0.2.2 allows remote attackers to bypass intended access restrictions for character encoding and the cookie secure flag via unknown vectors related to the "HTTP header rewrite function." | 2 | 5 | Medium | 2017-01-03 | 2009-03-13 | View | |
6030 | CVE-2008-6299 | Multiple cross-site scripting (XSS) vulnerabilities in Joomla! 1.5.7 and earlier allow remote authenticated users with certain privileges to inject arbitrary web script or HTML via (1) the title and description parameters to the com_weblinks module and (2) unspecified vectors in the com_content module related to "article submission." | 2 | 3.5 | Low | 2017-01-03 | 2009-08-13 | View |
Page 1206 of 17672, showing 5 records out of 88360 total, starting on record 6026, ending on 6030