NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 6445 | CVE-2008-6714 | admin.php in xeCMS 1.0.0 RC2 and earlier allows remote attackers to bypass authentication and access the admin panel by setting the xecms_username cookie. | 2 | 7.5 | High | 2017-01-03 | 2009-04-17 | View | |
| 6455 | CVE-2008-6724 | Cross-site scripting (XSS) vulnerability in index.pl in Perl Nopaste 1.0 allows remote attackers to inject arbitrary web script or HTML via the language parameter. NOTE: some of these details are obtained from third party information. | 2 | 4.3 | Medium | 2017-01-03 | 2009-04-17 | View | |
| 6456 | CVE-2008-6725 | Multiple SQL injection vulnerabilities in CMScout 2.06 allow remote authenticated users to execute arbitrary SQL commands via the id parameter to (1) index.php in a mythings page (mythings.php) and (2) the users page in admin.php. | 2 | 6 | Medium | 2017-01-03 | 2009-04-17 | View | |
| 6457 | CVE-2008-6726 | Multiple directory traversal vulnerabilities in CMScout 2.06, when register_globals is enabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the bit parameter to (1) admin.php and (2) index.php, different vectors than CVE-2008-3415. | 2 | 6 | Medium | 2017-01-03 | 2009-04-17 | View | |
| 5001 | CVE-2008-5217 | Directory traversal vulnerability in index.php in txtCMS 0.3, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the id parameter. | 2 | 5.1 | Medium | 2017-01-03 | 2009-04-17 | View |
Page 14681 of 17672, showing 5 records out of 88360 total, starting on record 73401, ending on 73405