NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 5405 | CVE-2008-5663 | Multiple unrestricted file upload vulnerabilities in Kusaba 1.0.4 and earlier allow remote authenticated users to execute arbitrary code by uploading a file with an executable extension using (1) load_receiver.php or (2) a shipainter action to paint_save.php, then accessing the uploaded file via a direct request to this file in their user directory. | 2 | 9 | High | 2017-01-03 | 2009-01-29 | View | |
| 5661 | CVE-2008-5930 | SQL injection vulnerability in admin/blog_comments.asp in The Net Guys ASPired2Blog allows remote attackers to execute arbitrary SQL commands via the BlogID parameter. | 2 | 7.5 | High | 2017-01-03 | 2009-01-29 | View | |
| 3358 | CVE-2008-3485 | Untrusted search path vulnerability in Citrix MetaFrame Presentation Server allows local users to gain privileges via a malicious icabar.exe placed in the search path. | 2 | 7.2 | High | 2017-01-03 | 2009-01-29 | View | |
| 5662 | CVE-2008-5931 | The Net Guys ASPired2Blog stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing usernames and passwords via a direct request for admin/blog.mdb. NOTE: some of these details are obtained from third party information. | 2 | 5 | Medium | 2017-01-03 | 2009-01-29 | View | |
| 1055 | CVE-2008-1094 | SQL injection vulnerability in index.cgi in the Account View page in Barracuda Spam Firewall (BSF) before 3.5.12.007 allows remote authenticated administrators to execute arbitrary SQL commands via a pattern_x parameter in a search_count_equals action, as demonstrated by the pattern_0 parameter. | 2 | 6.5 | Medium | 2017-01-03 | 2009-01-29 | View |
Page 14973 of 17672, showing 5 records out of 88360 total, starting on record 74861, ending on 74865