NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
6981 | CVE-2008-7250 | Cross-site scripting (XSS) vulnerability in Squid Analysis Report Generator (Sarg) 2.2.4 allows remote attackers to inject arbitrary web script or HTML via a JavaScript onload event in the User-Agent header, which is not properly handled when displaying the Squid proxy log. NOTE: this issue exists because of an incomplete fix for CVE-2008-1168. | 2 | 4.3 | Medium | 2017-01-03 | 2010-01-04 | View | |
6982 | CVE-2008-7251 | libraries/File.class.php in phpMyAdmin 2.11.x before 2.11.10 creates a temporary directory with 0777 permissions, which has unknown impact and attack vectors. | 2 | 10 | High | 2017-01-03 | 2010-05-06 | View | |
6983 | CVE-2008-7252 | libraries/File.class.php in phpMyAdmin 2.11.x before 2.11.10 uses predictable filenames for temporary files, which has unknown impact and attack vectors. | 2 | 10 | High | 2017-01-03 | 2011-01-28 | View | |
6984 | CVE-2008-7253 | The default configuration of the web server in IBM Lotus Domino Server, possibly 6.0 through 8.0, enables the HTTP TRACE method, which makes it easier for remote attackers to steal cookies and authentication credentials via a cross-site tracing (XST) attack, a related issue to CVE-2004-2763 and CVE-2005-3398. | 2 | 4.3 | Medium | 2017-01-03 | 2010-01-26 | View | |
6985 | CVE-2008-7254 | Directory traversal vulnerability in includes/template-loader.php in Irmin CMS (formerly Pepsi CMS) 0.5 and 0.6 BETA2, when register_globals is enabled, allows remote attackers to include and execute arbitrary files via a .. (dot dot) in the _Root_Path parameter. NOTE: some of these details are obtained from third party information. | 2 | 6.8 | Medium | 2017-01-03 | 2010-04-08 | View |
Page 1397 of 17672, showing 5 records out of 88360 total, starting on record 6981, ending on 6985