NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 6370 | CVE-2008-6639 | Cross-site request forgery (CSRF) vulnerability in admin.php in AjaXplorer 2.3.3 and 2.3.4 allows remote attackers to hijack the authentication of administrators for requests that modify passwords via the update_user_pwd action. | 2 | 6.8 | Medium | 2017-01-03 | 2009-04-07 | View | |
| 6372 | CVE-2008-6641 | Multiple SQL injection vulnerabilities in Shader TV (Beta) allow remote authenticated administrators to execute arbitrary SQL commands via the sid parameter to (1) kanal.asp, (2) google.asp, and (3) hakk.asp in yonet/; and allow remote attackers to execute arbitrary SQL commands via the (4) username or (5) password fields to yonet/default.asp. | 2 | 6.5 | Medium | 2017-01-03 | 2009-04-07 | View | |
| 6377 | CVE-2008-6646 | Cross-site scripting (XSS) vulnerability in index.php in CoronaMatrix phpAddressBook 2.0 allows remote attackers to inject arbitrary web script or HTML via the username parameter. | 2 | 4.3 | Medium | 2017-01-03 | 2009-04-07 | View | |
| 6381 | CVE-2008-6650 | del.php in miniBloggie 1.0 allows remote attackers to delete arbitrary posts via a direct request with a modified post_id parameter, a different vulnerability than CVE-2008-4628. | 2 | 5 | Medium | 2017-01-03 | 2009-04-07 | View | |
| 6382 | CVE-2008-6651 | Static code injection vulnerability in edithistory.php in OxYProject OxYBox 0.85 allows remote attackers to inject arbitrary PHP code into oxyhistory.php via the oxymsg parameter. | 2 | 10 | High | 2017-01-03 | 2009-04-07 | View |
Page 14730 of 17672, showing 5 records out of 88360 total, starting on record 73646, ending on 73650