NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
6241  CVE-2008-6510  Cross-site scripting (XSS) vulnerability in login.jsp in the Admin Console in Openfire 3.6.0a and earlier allows remote attackers to inject arbitrary web script or HTML via the url parameter.    4.3  Medium  2017-01-03  2009-03-25  View
6242  CVE-2008-6511  Open redirect vulnerability in login.jsp in Openfire 3.6.0a and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the url parameter.    5.8  Medium  2017-01-03  2009-03-25  View
6243  CVE-2008-6512  Cross-domain vulnerability in the WorkerPool API in Google Gears before 0.5.4.2 allows remote attackers to bypass the Same Origin Policy and the intended access restrictions of the allowCrossOrigin function by hosting an assumed-safe file type containing Google Gear commands on the target domain, then accessing that file from the attacking domain, whose response headers are not checked and cause the worker code to run in the target domain.    6.8  Medium  2017-01-03  2009-12-16  View
6244  CVE-2008-6513  Unrestricted file upload vulnerability in saa.php in Andy"s PHP Knowledgebase (aphpkb) 0.92.9 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a link that is listed by authors.php.    6.8  Medium  2017-01-03  2009-04-02  View
6245  CVE-2008-6514  The Expo plugin in Compiz Fusion 0.7.8 allows local users with physical access to drag the screen saver aside and access the locked desktop by using Expo mouse shortcuts, a related issue to CVE-2007-3920.    6.2  Medium  2017-01-03  2009-04-02  View

Page 1249 of 17672, showing 5 records out of 88360 total, starting on record 6241, ending on 6245

Actions