NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
6936 | CVE-2008-7205 | Unspecified vulnerability in the product view functionality in VirtueMart 1.0.13a and earlier allows remote attackers to read arbitrary files via vectors related to a template file. | 2 | 4.3 | Medium | 2017-01-03 | 2009-09-11 | View | |
6937 | CVE-2008-7206 | Unspecified vulnerability in Electronic Logbook (ELOG) before 2.7.2 has unknown impact and attack vectors when the "logbook contains HTML code," probably cross-site scripting (XSS). | 2 | 4.3 | Medium | 2017-01-03 | 2011-12-20 | View | |
6938 | CVE-2008-7207 | RivetTracker before 1.0 stores passwords in cleartext in config.php, which allows local users to discover passwords by reading config.php. | 2 | 2.1 | Low | 2017-01-03 | 2009-09-11 | View | |
6939 | CVE-2008-7208 | Multiple SQL injection vulnerabilities in OneCMS 2.4, and possibly earlier, allow remote attackers to execute arbitrary SQL commands via the (1) username parameter ($usernameb variable) to a_login.php or (2) user parameter to staff.php. | 2 | 6.8 | Medium | 2017-01-03 | 2009-09-15 | View | |
6940 | CVE-2008-7209 | Unrestricted file upload vulnerability in the add2 action in a_upload.php in OneCMS 2.4, and possibly earlier, allows remote attackers to execute arbitrary code by uploading a file with an executable extension and using a safe content type such as image/gif, then accessing it via a direct request to the file in an unspecified directory. | 2 | 7.5 | High | 2017-01-03 | 2009-09-15 | View |
Page 1388 of 17672, showing 5 records out of 88360 total, starting on record 6936, ending on 6940