NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
5400  CVE-2008-5658  Directory traversal vulnerability in the ZipArchive::extractTo function in PHP 5.2.6 and earlier allows context-dependent attackers to write arbitrary files via a ZIP file with a file whose name contains .. (dot dot) sequences.    7.5  High  2017-01-03  2009-10-31  View
5656  CVE-2008-5925  ASP-DEv XM Events Diary stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for diary.mdb.    Medium  2017-01-03  2009-01-23  View
5912  CVE-2008-6181  SQL injection vulnerability in the Mad4Joomla Mailforms (com_mad4joomla) component before 1.1.8.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the jid parameter to index.php.    7.5  High  2017-01-03  2009-02-20  View
6168  CVE-2008-6437  Multiple cross-site scripting (XSS) vulnerabilities in PHPFreeForum 1.0 RC2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) message parameter to error.php, and the (2) nickname and (3) randomid parameters to part/menu.php.    4.3  Medium  2017-01-03  2009-04-02  View
6424  CVE-2008-6693  SQL injection vulnerability in Download system (sb_downloader) extension 0.1.4 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unknown vectors.    7.5  High  2017-01-03  2009-08-20  View

Page 1446 of 17672, showing 5 records out of 88360 total, starting on record 7226, ending on 7230

Actions