NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
6811  CVE-2008-7080  Team PHP PHP Classifieds Script stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain database credentials via a direct request for admin/backup/datadump.sql.    Medium  2017-01-03  2009-08-25  View
6812  CVE-2008-7081  userHandler.cgi in RaidSonic ICY BOX NAS firmware 2.3.2.IB.2.RS.1 allows remote attackers to bypass authentication and gain administrator privileges by setting the login parameter to admin. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.    10  High  2017-01-03  2009-08-26  View
6813  CVE-2008-7082  MyBB (aka MyBulletinBoard) 1.4.3 includes the sensitive my_post_key parameter in URLs to moderation.php with the (1) mergeposts, (2) split, and (3) deleteposts actions, which allows remote attackers to steal the token and bypass the cross-site request forgery (CSRF) protection mechanism to hijack the authentication of moderators by reading the token from the HTTP Referer header.    6.8  Medium  2017-01-03  2009-08-26  View
6814  CVE-2008-7083  Multiple SQL injection vulnerabilities in ReVou Micro Blogging Twitter clone allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password fields.    7.5  High  2017-01-03  2009-08-25  View
6815  CVE-2008-7084  Directory traversal vulnerability in the web server 1.0 in Velocity Security Management System allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.    Medium  2017-01-03  2009-08-26  View

Page 1363 of 17672, showing 5 records out of 88360 total, starting on record 6811, ending on 6815

Actions