NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
5448  CVE-2008-5706  The cTrigger::DoIt function in src/ctrigger.cpp in the trigger mechanism in the daemon in Verlihub 0.9.8d-RC2 and earlier allows local users to overwrite arbitrary files via a symlink attack on the /tmp/trigger.tmp temporary file.    6.9  Medium  2017-01-03  2009-01-29  View
5704  CVE-2008-5973  SQL injection vulnerability in login.aspx in Active Web Mail 4.0 allows remote attackers to execute arbitrary SQL commands via the password parameter.    7.5  High  2017-01-03  2009-01-27  View
5960  CVE-2008-6229  Cross-site scripting (XSS) vulnerability in the administrative interface in Drupal Content Construction Kit (CCK) 5.x before 5.x-1.10 and 6.x before 6.x-2.0, a module for Drupal, allows remote authenticated users with "administer content" permissions to inject arbitrary web script or HTML via (1) field labels and (2) content-type names.    3.5  Low  2017-01-03  2011-03-07  View
6216  CVE-2008-6485  SQL injection vulnerability in index.php in SoftComplex PHP Image Gallery allows remote attackers to execute arbitrary SQL commands via the ctg parameter.    7.5  High  2017-01-03  2009-03-19  View
6472  CVE-2008-6741  SQL injection vulnerability in Load.php in Simple Machines Forum (SMF) 1.1.4 and earlier allows remote attackers to execute arbitrary SQL commands by setting the db_character_set parameter to a multibyte character set such as big5, which causes the addslashes PHP function to produce a "" (backslash) sequence that does not quote the """ (single quote) character, as demonstrated via a manlabels action to index.php.    7.5  High  2017-01-03  2009-04-22  View

Page 14522 of 17672, showing 5 records out of 88360 total, starting on record 72606, ending on 72610

Actions