NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
6231 | CVE-2008-6500 | Cross-site scripting (XSS) vulnerability in CodeToad ASP Shopping Cart Script allows remote attackers to inject arbitrary web script or HTML via the query string to the default URI. | 2 | 4.3 | Medium | 2017-01-03 | 2009-03-20 | View | |
6232 | CVE-2008-6501 | Cross-site scripting (XSS) vulnerability in profiles/index.php in Pro Chat Rooms 3.0.2 allows remote attackers to inject arbitrary web script or HTML via the gud parameter. | 2 | 4.3 | Medium | 2017-01-03 | 2009-10-06 | View | |
6233 | CVE-2008-6502 | Directory traversal vulnerability in Pro Chat Rooms 3.0.2 allows remote authenticated users to select an arbitrary local PHP script as an avatar via a .. (dot dot) in the avatar parameter, and cause other users to execute this script by using sendData.php to send a message to (1) an individual user or (2) a room, leading to cross-site request forgery (CSRF), cross-site scripting (XSS), or other impacts. | 2 | 4.6 | Medium | 2017-01-03 | 2009-10-06 | View | |
6234 | CVE-2008-6503 | Multiple cross-site scripting (XSS) vulnerabilities in PrestaShop 1.1.0.3 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) admin/login.php and (2) order.php. | 2 | 4.3 | Medium | 2017-01-03 | 2009-03-20 | View | |
6235 | CVE-2008-6504 | ParametersInterceptor in OpenSymphony XWork 2.0.x before 2.0.6 and 2.1.x before 2.1.2, as used in Apache Struts and other products, does not properly restrict # (pound sign) references to context objects, which allows remote attackers to execute Object-Graph Navigation Language (OGNL) statements and modify server-side context objects, as demonstrated by use of a u0023 representation for the # character. | 2 | 5 | Medium | 2017-01-03 | 2015-07-28 | View |
Page 1247 of 17672, showing 5 records out of 88360 total, starting on record 6231, ending on 6235