NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
6206 | CVE-2008-6475 | SQL injection vulnerability in the guestbook component (components/guestbook/guestbook.php) in Drake CMS 0.4.11 and earlier allows remote attackers to execute arbitrary SQL commands via the Via HTTP header (HTTP_VIA) to index.php. | 2 | 7.5 | High | 2017-01-03 | 2009-03-16 | View | |
6207 | CVE-2008-6476 | Cross-site scripting (XSS) vulnerability in blog/search.aspx in BlogEngine.NET allows remote attackers to inject arbitrary web script or HTML via the q parameter. | 2 | 4.3 | Medium | 2017-01-03 | 2009-04-01 | View | |
6208 | CVE-2008-6477 | SQL injection vulnerability in Mumbo Jumbo Media OP4 allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php. | 2 | 7.5 | High | 2017-01-03 | 2009-03-20 | View | |
6209 | CVE-2008-6478 | Cross-site request forgery (CSRF) vulnerability in the file manager in the VZPP web interface for Parallels Virtuozzo 365.6.swsoft (build 4.0.0-365.6.swsoft) and 25.4.swsoft (build 3.0.0-25.4.swsoft) allows remote attackers to create and delete arbitrary files as the administrator via a link or IMG tag to (1) create-file and (2) list-control in vz/cp/vzdir/infrman/envs/files/; or modify system configuration via the path parameter to vz/cp/vzdir/infrman/envs/files/index. | 2 | 6.8 | Medium | 2017-01-03 | 2009-03-17 | View | |
6210 | CVE-2008-6479 | Cross-site request forgery (CSRF) vulnerability in the "change password" feature in the VZPP web interface for Parallels Virtuozzo 25.4.swsoft (build 3.0.0-25.4.swsoft) allows remote attackers to modify the password via a link or IMG tag to vz/cp/pwd. | 2 | 6.8 | Medium | 2017-01-03 | 2009-03-17 | View |
Page 1242 of 17672, showing 5 records out of 88360 total, starting on record 6206, ending on 6210