NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 2558 | CVE-2008-2652 | Multiple SQL injection vulnerabilities in catalog.php in SMEWeb 1.4b and 1.4f allow remote attackers to execute arbitrary SQL commands via the (1) idp and (2) category parameters. | 2 | 7.5 | High | 2017-01-03 | 2009-04-14 | View | |
| 6415 | CVE-2008-6684 | Unrestricted file upload vulnerability in editimage.php in Apartment Search Script allows remote attackers to execute arbitrary code by uploading a file with an executable extension and a GIF header, then accessing this file via a direct request to a renamed file in Member_Admin/logo/. | 2 | 6.8 | Medium | 2017-01-03 | 2009-04-13 | View | |
| 6431 | CVE-2008-6700 | Multiple cross-site scripting (XSS) vulnerabilities in Butterfly Organizer 2.0.0 allow remote attackers to inject arbitrary web script or HTML via the (1) mytable parameter to view.php, (2) mytable parameter to viewdb2.php, (3) tablehere parameter to category-rename.php, and (4) letter parameter to module-contacts.php. | 2 | 4.3 | Medium | 2017-01-03 | 2009-04-13 | View | |
| 6432 | CVE-2008-6701 | NetScout (formerly Network General) Visualizer V2100 and InfiniStream i1730 do not restrict access to ResourceManager/en_US/domains/add_domain.jsp, which allows remote attackers to gain administrator privileges via a direct request. | 2 | 7.5 | High | 2017-01-03 | 2009-04-13 | View | |
| 6443 | CVE-2008-6712 | The HTTP/XML-RPC service in Crysis 1.21 (game version 1.1.1.6156) and earlier allows remote attackers to cause a denial of service (crash) via a long HTTP request, which triggers a NULL pointer dereference. | 2 | 5 | Medium | 2017-01-03 | 2009-04-13 | View |
Page 14706 of 17672, showing 5 records out of 88360 total, starting on record 73526, ending on 73530