NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
6476 | CVE-2008-6745 | index.php in BlogPHP 2.0 allows remote attackers to gain administrator privileges via a crafted email parameter in a register2 action. | 2 | 7.5 | High | 2017-01-03 | 2009-04-23 | View | |
6477 | CVE-2008-6746 | Cross-site scripting (XSS) vulnerability in the contact display view in Turba Contact Manager H3 before 2.2.1 allows remote attackers to inject arbitrary web script or HTML via the contact name. | 2 | 4.3 | Medium | 2017-01-03 | 2009-04-23 | View | |
6478 | CVE-2008-6747 | dotProject before 2.1.2 does not properly restrict access to administrative pages, which allows remote attackers to gain privileges. NOTE: some of these details are obtained from third party information. | 2 | 6.8 | Medium | 2017-01-03 | 2009-04-23 | View | |
6479 | CVE-2008-6748 | Eval injection vulnerability in Megacubo 5.0.7 allows remote attackers to inject and execute arbitrary PHP code via the play action in a mega:// URI. | 2 | 9.3 | High | 2017-01-03 | 2009-06-15 | View | |
6480 | CVE-2008-6749 | Multiple SQL injection vulnerabilities in admin/usercheck.php in FlexPHPDirectory 0.0.1, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) checkuser and (2) checkpass parameters. | 2 | 6.8 | Medium | 2017-01-03 | 2013-08-27 | View |
Page 1296 of 17672, showing 5 records out of 88360 total, starting on record 6476, ending on 6480