NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
6466  CVE-2008-6735  Directory traversal vulnerability in qc/index.php in ThaiQuickCart 3 allows remote attackers to read arbitrary files via a .. (dot dot) in the sLanguage cookie.    5.8  Medium  2017-01-03  2009-04-22  View
6467  CVE-2008-6736  Flat Calendar 1.1 does not properly restrict access to administrative functions, which allows remote attackers to (1) add new events via calAdd.php, as reachable from admin/add.php, or (2) delete events via admin/deleteEvent.php. NOTE: this is only a vulnerability when the administrator does not follow recommendations in the product"s security documentation.    6.4  Medium  2017-01-03  2009-04-22  View
6468  CVE-2008-6737  Crysis 1.21 and earlier allows remote attackers to obtain sensitive player information such as real IP addresses by sending a keyexchange packet without a previous join packet, which causes Crysis to send a disconnect packet that includes unrelated log information.    7.8  High  2017-01-03  2009-04-22  View
6469  CVE-2008-6738  MyShoutPro 1.2 allows remote attackers to bypass authentication and gain administrative access by setting the admin_access cookie to 1.    7.5  High  2017-01-03  2009-04-22  View
6470  CVE-2008-6739  Todd Woolums ASP Download management script 1.03 does not require authentication for setupdownload.asp, which allows remote attackers to gain administrator privileges via a direct request.    7.5  High  2017-01-03  2009-04-22  View

Page 1294 of 17672, showing 5 records out of 88360 total, starting on record 6466, ending on 6470

Actions