NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
6606 | CVE-2008-6875 | SQL injection vulnerability in default.asp in ASP Product Catalog allows remote attackers to execute arbitrary SQL commands via the cid parameter, a different vector than CVE-2007-5220. | 2 | 7.5 | High | 2017-01-03 | 2013-09-05 | View | |
6607 | CVE-2008-6876 | Cross-site scripting (XSS) vulnerability in login.php in EsPartenaires 1.0 allows remote attackers to inject arbitrary web script or HTML via the msg parameter. NOTE: the EsContacts 1.0 issue is covered in CVE-2008-2037. | 2 | 4.3 | Medium | 2017-01-03 | 2009-08-19 | View | |
6608 | CVE-2008-6877 | ** DISPUTED ** Directory traversal vulnerability in admin/includes/initsystem.php in Zen Cart 1.3.8 and 1.3.8a, when .htaccess is not supported, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the loader_file parameter. NOTE: the vendor disputes this issue, stating "at worst, the use of this vulnerability will reveal some local file paths." | 2 | 6.8 | Medium | 2017-01-03 | 2009-07-28 | View | |
6609 | CVE-2008-6878 | ** DISPUTED ** Directory traversal vulnerability in admin/includes/languages/english.php in Zen Cart 1.3.8a, 1.3.8, and earlier, when .htaccess is not supported, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the _SESSION[language] parameter. NOTE: the vendor disputes this issue, stating "at worst, the use of this vulnerability will reveal some local file paths." | 2 | 6.8 | Medium | 2017-01-03 | 2009-07-28 | View | |
6610 | CVE-2008-6879 | Cross-site scripting (XSS) vulnerability in Apache Roller 2.3, 3.0, 3.1, and 4.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter in a search action. | 2 | 4.3 | Medium | 2017-01-03 | 2009-07-31 | View |
Page 1322 of 17672, showing 5 records out of 88360 total, starting on record 6606, ending on 6610