NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
6811 | CVE-2008-7080 | Team PHP PHP Classifieds Script stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain database credentials via a direct request for admin/backup/datadump.sql. | 2 | 5 | Medium | 2017-01-03 | 2009-08-25 | View | |
6812 | CVE-2008-7081 | userHandler.cgi in RaidSonic ICY BOX NAS firmware 2.3.2.IB.2.RS.1 allows remote attackers to bypass authentication and gain administrator privileges by setting the login parameter to admin. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | 2 | 10 | High | 2017-01-03 | 2009-08-26 | View | |
6813 | CVE-2008-7082 | MyBB (aka MyBulletinBoard) 1.4.3 includes the sensitive my_post_key parameter in URLs to moderation.php with the (1) mergeposts, (2) split, and (3) deleteposts actions, which allows remote attackers to steal the token and bypass the cross-site request forgery (CSRF) protection mechanism to hijack the authentication of moderators by reading the token from the HTTP Referer header. | 2 | 6.8 | Medium | 2017-01-03 | 2009-08-26 | View | |
6814 | CVE-2008-7083 | Multiple SQL injection vulnerabilities in ReVou Micro Blogging Twitter clone allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password fields. | 2 | 7.5 | High | 2017-01-03 | 2009-08-25 | View | |
6815 | CVE-2008-7084 | Directory traversal vulnerability in the web server 1.0 in Velocity Security Management System allows remote attackers to read arbitrary files via a .. (dot dot) in the URI. | 2 | 5 | Medium | 2017-01-03 | 2009-08-26 | View |
Page 1363 of 17672, showing 5 records out of 88360 total, starting on record 6811, ending on 6815