NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 5410 | CVE-2008-5668 | Multiple cross-site scripting (XSS) vulnerabilities in Textpattern (aka Txp CMS) 4.0.5 allow remote attackers to inject arbitrary web script or HTML via (1) the PATH_INFO to setup/index.php or (2) the name parameter to index.php in the comments preview section. | 2 | 4.3 | Medium | 2017-01-03 | 2009-01-29 | View | |
| 5666 | CVE-2008-5935 | Facto stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing the password via a direct request for database/facto.mdb. NOTE: some of these details are obtained from third party information. | 2 | 5 | Medium | 2017-01-03 | 2009-01-29 | View | |
| 5411 | CVE-2008-5669 | index.php in the comments preview section in Textpattern (aka Txp CMS) 4.0.5 allows remote attackers to cause a denial of service via a long message parameter. | 2 | 5 | Medium | 2017-01-03 | 2009-01-29 | View | |
| 2596 | CVE-2008-2698 | Multiple cross-site scripting (XSS) vulnerabilities in photo_add-c.php (aka the "add comment" section) in WEBalbum 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) comment, (2) id, or (3) category parameter. | 2 | 4.3 | Medium | 2017-01-03 | 2009-01-29 | View | |
| 5412 | CVE-2008-5670 | Textpattern (aka Txp CMS) 4.0.5 does not ask for the old password during a password reset, which makes it easier for remote attackers to change a password after hijacking a session. | 2 | 6.8 | Medium | 2017-01-03 | 2009-01-29 | View |
Page 14976 of 17672, showing 5 records out of 88360 total, starting on record 74876, ending on 74880