NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
2369  CVE-2008-2455  SQL injection vulnerability in comment.php in the MacGuru BLOG Engine plugin 2.2 for e107 allows remote attackers to execute arbitrary SQL commands via the rid parameter.    7.5  High  2017-01-03  2009-04-02  View
6211  CVE-2008-6480  Cross-site request forgery (CSRF) vulnerability in engine/modules/imagepreview.php in Datalife Engine 6.7 allows remote attackers to hijack the authentication of arbitrary users for requests that use a modified image parameter.    6.8  Medium  2017-01-03  2009-04-02  View
2127  CVE-2008-2200  Multiple cross-site scripting (XSS) vulnerabilities in Maian Weblog 4.0 allow remote attackers to inject arbitrary web script or HTML via the (1) keywords parameter to admin/index.php in a blogs search action, the (2) msg_charset and (3) msg_header9 parameters to admin/inc/header.php, and the (4) keywords parameter to index.php in a search action.    4.3  Medium  2017-01-03  2009-04-02  View
48463  CVE-2009-1170  Unspecified vulnerability in Sun OpenSolaris snv_100 through snv_101 allows local users, with privileges in a non-global zone, to execute arbitrary code in the global zone when a global-zone user is using mdb on a non-global zone process.    6.9  Medium  2017-01-07  2009-04-02  View
6224  CVE-2008-6493  Easy Content Management Publishing stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for Database/News.mdb.    Medium  2017-01-03  2009-04-02  View

Page 14746 of 17672, showing 5 records out of 88360 total, starting on record 73726, ending on 73730

Actions