NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
2322 | CVE-2008-2406 | The administration application server in Sun Java Active Server Pages (ASP) Server before 4.0.3 allows remote attackers to bypass authentication via direct requests on TCP port 5102. | 2 | 7.5 | High | 2017-01-03 | 2011-03-07 | View | |
67858 | CVE-2005-2154 | PHP local file inclusion vulnerability in (1) view.php and (2) open.php in osTicket 1.3.1 beta and earlier allows remote attackers to include and possibly execute arbitrary local files via the inc parameter. | 2 | 7.5 | High | 2017-01-03 | 2008-09-05 | View | |
2578 | CVE-2008-2680 | Multiple cross-site scripting (XSS) vulnerabilities in _db/compact.asp in Realm CMS 2.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) CmpctedDB and (2) Boyut parameters. | 2 | 4.3 | Medium | 2017-01-03 | 2008-09-10 | View | |
68114 | CVE-2005-2423 | Beehive Forum allows remote attackers to obtain sensitive information via (1) an invalid final_uri or sort_by parameter to index.php or a direct request to (2) admin.php, (3) attachments.inc.php, (4) banned.inc.php, (5) beehive.inc.php, (6) constants.inc.php, (7) db.inc.php, (8) dictionary.inc.php or (9) search_index.php, which reveal the path in an error message. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
2834 | CVE-2008-2940 | The alert-mailing implementation in HP Linux Imaging and Printing (HPLIP) 1.6.7 allows local users to gain privileges and send e-mail messages from the root account via vectors related to the setalerts message, and lack of validation of the device URI associated with an event message. | 2 | 7.2 | High | 2017-01-03 | 2012-10-30 | View |
Page 1228 of 17672, showing 5 records out of 88360 total, starting on record 6136, ending on 6140