NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 5756 | CVE-2008-6025 | Directory traversal vulnerability in scr/form.php in openElec 3.01 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the obj parameter. | 2 | 6.8 | Medium | 2017-01-03 | 2009-08-19 | View | |
| 6012 | CVE-2008-6281 | SQL injection vulnerability in index.php in Bluo CMS 1.2 allows remote attackers to execute arbitrary SQL commands via the id parameter. | 2 | 7.5 | High | 2017-01-03 | 2009-02-26 | View | |
| 6268 | CVE-2008-6537 | LightNEasy/lightneasy.php in LightNEasy No database version 1.2 allows remote attackers to obtain the hash of the administrator password via the setup "do" action to LightNEasy.php, which is cleared from $_GET but later accessed using $_REQUEST. | 2 | 5 | Medium | 2017-01-03 | 2009-03-30 | View | |
| 6524 | CVE-2008-6793 | The get_file_type function in lib/file_content.php in DFLabs PTK 0.1, 0.2, and 1.0 allows remote attackers to execute arbitrary commands via shell metacharacters after an arg1= sequence in a filename within a forensic image. | 2 | 6.8 | Medium | 2017-01-03 | 2009-08-11 | View | |
| 6780 | CVE-2008-7049 | Multiple SQL injection vulnerabilities in login.asp in NatterChat 1.1 and 1.12 allow remote attackers to execute arbitrary SQL commands via the (1) txtUsername parameter (aka Username) and (2) txtPassword parameter (aka Password) in a form generated by home.asp. NOTE: due to lack of details, it is not clear whether this is related to CVE-2004-2206. | 2 | 7.5 | High | 2017-01-03 | 2009-08-24 | View |
Page 15006 of 17672, showing 5 records out of 88360 total, starting on record 75026, ending on 75030