NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
5396  CVE-2008-5654  SQL injection vulnerability in the loginADP function in ajaxp.php in MyioSoft EasyCalendar 4.0 allows remote attackers to execute arbitrary SQL commands via the rsargs parameter, as reachable through the username parameter, a different vector than CVE-2008-1344. NOTE: some of these details are obtained from third party information.    7.5  High  2017-01-03  2008-12-24  View
5652  CVE-2008-5921  SQL injection vulnerability in albums.php in Umer Inc Songs Portal allows remote attackers to execute arbitrary SQL commands via the id parameter.    7.5  High  2017-01-03  2009-01-29  View
5908  CVE-2008-6177  Multiple directory traversal vulnerabilities in LightBlog 9.8, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) username parameter to view_member.php, (2) username_post parameter to login.php, and the (3) Lightblog_username cookie parameter to check_user.php.    6.8  Medium  2017-01-03  2009-04-30  View
6164  CVE-2008-6433  Cross-site scripting (XSS) vulnerability in index.cfm in Blue River Interactive Group Sava CMS before 5.0.122 allows remote attackers to inject arbitrary web script or HTML via the keywords parameter in a search action.    4.3  Medium  2017-01-03  2009-04-02  View
6420  CVE-2008-6689  SQL injection vulnerability in JobControl (dmmjobcontrol) 1.15.0 and earlier extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unknown vectors.    7.5  High  2017-01-03  2009-08-19  View

Page 1206 of 17672, showing 5 records out of 88360 total, starting on record 6026, ending on 6030

Actions