NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
6661 | CVE-2008-6930 | Unrestricted file upload vulnerability in PHPStore Real Estate allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a logo, then accessing it via a direct request to the file in realty/re_images/. | 2 | 6.5 | Medium | 2017-01-03 | 2009-08-19 | View | |
6662 | CVE-2008-6931 | Unrestricted file upload vulnerability in PHPStore Job Search (aka PHPCareers) allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a resume photo, then accessing it via a direct request to the file in jobseekers/jobseeker_profile_images. | 2 | 6.5 | Medium | 2017-01-03 | 2009-08-19 | View | |
6663 | CVE-2008-6932 | Unrestricted file upload vulnerability in submit_file.php in AlstraSoft SendIt Pro allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in send/files/. | 2 | 7.5 | High | 2017-01-03 | 2009-08-12 | View | |
6664 | CVE-2008-6933 | Directory traversal vulnerability in index.php in MiniGal b13 (aka MG2) allows remote attackers to read the source code of .php files, and possibly the content of other files, via a .. (dot dot) in the list parameter. | 2 | 5 | Medium | 2017-01-03 | 2009-08-12 | View | |
6665 | CVE-2008-6934 | Static code injection vulnerability in Sanus|artificium (aka Sanusart) Free simple guestbook PHP script, when downloaded before 20081111, allows remote attackers to inject arbitrary PHP code into messages.txt via the message parameter to act.php, which is executed when guestbook/guestbook.php is accessed. NOTE: some of these details are obtained from third party information. | 2 | 7.5 | High | 2017-01-03 | 2009-08-12 | View |
Page 1333 of 17672, showing 5 records out of 88360 total, starting on record 6661, ending on 6665