NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
6396  CVE-2008-6665  change.php in Ananta CMS 1.0b5, with magic_quotes_gpc disabled, allows remote attackers to gain administrator privileges via a crafted email parameter, possibly related to code injection.    6.8  Medium  2017-01-03  2009-04-22  View
6397  CVE-2008-6666  Multiple cross-site scripting (XSS) vulnerabilities in Kronos webTA allow remote attackers to inject arbitrary web script or HTML via the description field to (1) servlet/com.threeis.webta.H710selProject and (2) servlet/com.threeis.webta.H720editProjectInfo. NOTE: BID:29610 states that the initial report was incorrect, but the reason for this conclusion is unknown.    4.3  Medium  2017-01-03  2009-04-08  View
6398  CVE-2008-6667  A+ PHP Scripts News Management System (NMS) allows remote attackers to bypass authentication and gain administrator privileges by setting the mobsuser and mobspass cookies to 1.    7.5  High  2017-01-03  2009-08-19  View
6399  CVE-2008-6668  Multiple directory traversal vulnerabilities in nweb2fax 0.2.7 and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) id parameter to comm.php and (2) var_filename parameter to viewrq.php.    Medium  2017-01-03  2009-04-08  View
6400  CVE-2008-6669  viewrq.php in nweb2fax 0.2.7 and earlier allows remote attackers to execute arbitrary code via shell metacharacters in the var_filename parameter in a (1) tif or (2) pdf format action.    7.5  High  2017-01-03  2009-04-08  View

Page 1280 of 17672, showing 5 records out of 88360 total, starting on record 6396, ending on 6400

Actions