NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
6396 | CVE-2008-6665 | change.php in Ananta CMS 1.0b5, with magic_quotes_gpc disabled, allows remote attackers to gain administrator privileges via a crafted email parameter, possibly related to code injection. | 2 | 6.8 | Medium | 2017-01-03 | 2009-04-22 | View | |
6397 | CVE-2008-6666 | Multiple cross-site scripting (XSS) vulnerabilities in Kronos webTA allow remote attackers to inject arbitrary web script or HTML via the description field to (1) servlet/com.threeis.webta.H710selProject and (2) servlet/com.threeis.webta.H720editProjectInfo. NOTE: BID:29610 states that the initial report was incorrect, but the reason for this conclusion is unknown. | 2 | 4.3 | Medium | 2017-01-03 | 2009-04-08 | View | |
6398 | CVE-2008-6667 | A+ PHP Scripts News Management System (NMS) allows remote attackers to bypass authentication and gain administrator privileges by setting the mobsuser and mobspass cookies to 1. | 2 | 7.5 | High | 2017-01-03 | 2009-08-19 | View | |
6399 | CVE-2008-6668 | Multiple directory traversal vulnerabilities in nweb2fax 0.2.7 and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) id parameter to comm.php and (2) var_filename parameter to viewrq.php. | 2 | 5 | Medium | 2017-01-03 | 2009-04-08 | View | |
6400 | CVE-2008-6669 | viewrq.php in nweb2fax 0.2.7 and earlier allows remote attackers to execute arbitrary code via shell metacharacters in the var_filename parameter in a (1) tif or (2) pdf format action. | 2 | 7.5 | High | 2017-01-03 | 2009-04-08 | View |
Page 1280 of 17672, showing 5 records out of 88360 total, starting on record 6396, ending on 6400