NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
6370  CVE-2008-6639  Cross-site request forgery (CSRF) vulnerability in admin.php in AjaXplorer 2.3.3 and 2.3.4 allows remote attackers to hijack the authentication of administrators for requests that modify passwords via the update_user_pwd action.    6.8  Medium  2017-01-03  2009-04-07  View
6372  CVE-2008-6641  Multiple SQL injection vulnerabilities in Shader TV (Beta) allow remote authenticated administrators to execute arbitrary SQL commands via the sid parameter to (1) kanal.asp, (2) google.asp, and (3) hakk.asp in yonet/; and allow remote attackers to execute arbitrary SQL commands via the (4) username or (5) password fields to yonet/default.asp.    6.5  Medium  2017-01-03  2009-04-07  View
6377  CVE-2008-6646  Cross-site scripting (XSS) vulnerability in index.php in CoronaMatrix phpAddressBook 2.0 allows remote attackers to inject arbitrary web script or HTML via the username parameter.    4.3  Medium  2017-01-03  2009-04-07  View
6381  CVE-2008-6650  del.php in miniBloggie 1.0 allows remote attackers to delete arbitrary posts via a direct request with a modified post_id parameter, a different vulnerability than CVE-2008-4628.    Medium  2017-01-03  2009-04-07  View
6382  CVE-2008-6651  Static code injection vulnerability in edithistory.php in OxYProject OxYBox 0.85 allows remote attackers to inject arbitrary PHP code into oxyhistory.php via the oxymsg parameter.    10  High  2017-01-03  2009-04-07  View

Page 14730 of 17672, showing 5 records out of 88360 total, starting on record 73646, ending on 73650

Actions