NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
5632  CVE-2008-5901  iyzi Forum 1.0 beta 3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing a password via a direct request for db/iyziforum.mdb. NOTE: some of these details are obtained from third party information.    7.5  High  2017-01-03  2009-01-29  View
2049  CVE-2008-2115  Multiple cross-site scripting (XSS) vulnerabilities in editor.php in ScriptsEZ.net Power Editor 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) te and (2) dir parameters in a tempedit action.    4.3  Medium  2017-01-03  2009-01-29  View
3329  CVE-2008-3448  Cross-site scripting (XSS) vulnerability in index.php in common solutions csphonebook 1.02 allows remote attackers to inject arbitrary web script or HTML via the letter parameter.    4.3  Medium  2017-01-03  2009-01-29  View
2050  CVE-2008-2116  Multiple directory traversal vulnerabilities in editor.php in ScriptsEZ.net Power Editor 2.0 allow remote attackers to read arbitrary local files via a .. (dot dot) in the (1) te and (2) dir parameters in a tempedit action.    4.4  Medium  2017-01-03  2009-01-29  View
3074  CVE-2008-3191  Multiple SQL injection vulnerabilities in usercp.php in mForum 0.1a, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) City, (2) Interest, (3) Email, (4) Icq, (5) msn, or (6) Yahoo Messenger field in an edit_profile action.    6.8  Medium  2017-01-03  2009-01-29  View

Page 14961 of 17672, showing 5 records out of 88360 total, starting on record 74801, ending on 74805

Actions