NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
6556  CVE-2008-6825  Directory traversal vulnerability in user/index.php in Fonality trixbox CE 2.6.1 and earlier allows remote attackers to include and execute arbitrary files via a .. (dot dot) in the langChoice parameter.    6.8  Medium  2017-01-03  2009-06-08  View
6557  CVE-2008-6826  dhtml.pl in MHF Media Pro allows remote attackers to execute arbitrary commands via shell metacharacters in the page parameter, as demonstrated using the (1) advert_top.htm or (2) advert_login.htm pages.    10  High  2017-01-03  2009-06-09  View
6558  CVE-2008-6827  The ListView control in the Client GUI (AClient.exe) in Symantec Altiris Deployment Solution 6.x before 6.9.355 SP1 allows local users to gain SYSTEM privileges and execute arbitrary commands via a "Shatter" style attack on the "command prompt" hidden GUI button to (1) overwrite the CommandLine parameter to cmd.exe to use SYSTEM privileges and (2) modify the DLL that is loaded using the LoadLibrary API function.    6.8  Medium  2017-01-03  2009-06-09  View
6559  CVE-2008-6828  Symantec Altiris Deployment Solution 6.x before 6.9.355 SP1 stores the Application Identity Account password in memory in cleartext, which allows local users to gain privileges and modify clients of the Deployment Solution Server.    4.3  Medium  2017-01-03  2009-06-09  View
6560  CVE-2008-6829  VicFTPS 5.0 allows remote attackers to cause a denial of service (crash) via a LIST command that starts with a "//" (forward slash, backward slash, forward slash). NOTE: this might be the same issue as CVE-2008-2031.    Medium  2017-01-03  2009-06-09  View

Page 1312 of 17672, showing 5 records out of 88360 total, starting on record 6556, ending on 6560

Actions