NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
5400 | CVE-2008-5658 | Directory traversal vulnerability in the ZipArchive::extractTo function in PHP 5.2.6 and earlier allows context-dependent attackers to write arbitrary files via a ZIP file with a file whose name contains .. (dot dot) sequences. | 2 | 7.5 | High | 2017-01-03 | 2009-10-31 | View | |
5656 | CVE-2008-5925 | ASP-DEv XM Events Diary stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for diary.mdb. | 2 | 5 | Medium | 2017-01-03 | 2009-01-23 | View | |
5912 | CVE-2008-6181 | SQL injection vulnerability in the Mad4Joomla Mailforms (com_mad4joomla) component before 1.1.8.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the jid parameter to index.php. | 2 | 7.5 | High | 2017-01-03 | 2009-02-20 | View | |
6168 | CVE-2008-6437 | Multiple cross-site scripting (XSS) vulnerabilities in PHPFreeForum 1.0 RC2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) message parameter to error.php, and the (2) nickname and (3) randomid parameters to part/menu.php. | 2 | 4.3 | Medium | 2017-01-03 | 2009-04-02 | View | |
6424 | CVE-2008-6693 | SQL injection vulnerability in Download system (sb_downloader) extension 0.1.4 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unknown vectors. | 2 | 7.5 | High | 2017-01-03 | 2009-08-20 | View |
Page 1446 of 17672, showing 5 records out of 88360 total, starting on record 7226, ending on 7230