NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
6445  CVE-2008-6714  admin.php in xeCMS 1.0.0 RC2 and earlier allows remote attackers to bypass authentication and access the admin panel by setting the xecms_username cookie.    7.5  High  2017-01-03  2009-04-17  View
6455  CVE-2008-6724  Cross-site scripting (XSS) vulnerability in index.pl in Perl Nopaste 1.0 allows remote attackers to inject arbitrary web script or HTML via the language parameter. NOTE: some of these details are obtained from third party information.    4.3  Medium  2017-01-03  2009-04-17  View
6456  CVE-2008-6725  Multiple SQL injection vulnerabilities in CMScout 2.06 allow remote authenticated users to execute arbitrary SQL commands via the id parameter to (1) index.php in a mythings page (mythings.php) and (2) the users page in admin.php.    Medium  2017-01-03  2009-04-17  View
6457  CVE-2008-6726  Multiple directory traversal vulnerabilities in CMScout 2.06, when register_globals is enabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the bit parameter to (1) admin.php and (2) index.php, different vectors than CVE-2008-3415.    Medium  2017-01-03  2009-04-17  View
5001  CVE-2008-5217  Directory traversal vulnerability in index.php in txtCMS 0.3, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the id parameter.    5.1  Medium  2017-01-03  2009-04-17  View

Page 14681 of 17672, showing 5 records out of 88360 total, starting on record 73401, ending on 73405

Actions