NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 2714 | CVE-2008-2820 | Directory traversal vulnerability in lang/lang-system.php in Open Azimyt CMS 0.22 minimal and 0.21 stable allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter. | 2 | 6.4 | Medium | 2017-01-03 | 2009-01-29 | View | |
| 3226 | CVE-2008-3345 | SQL injection vulnerability in staticpages/easyecards/index.php in MyioSoft EasyE-Cards 3.5 trial edition (tr) and 3.10a, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the sid parameter in a pickup action. | 2 | 6.8 | Medium | 2017-01-03 | 2009-01-29 | View | |
| 4250 | CVE-2008-4425 | Directory traversal vulnerability in upload.php in Phlatline"s Personal Information Manager (pPIM) 1.0 allows remote attackers to delete arbitrary files via directory traversal sequences in the file parameter within a delfile action. | 2 | 8.8 | High | 2017-01-03 | 2009-01-29 | View | |
| 5274 | CVE-2008-5525 | ClamAV 0.94.1 and possibly 0.93.1, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit. | 2 | 9.3 | High | 2017-01-03 | 2009-01-29 | View | |
| 4251 | CVE-2008-4426 | Cross-site scripting (XSS) vulnerability in events.php in Phlatline"s Personal Information Manager (pPIM) 1.0 allows remote attackers to inject arbitrary web script or HTML via the date parameter in a new action. | 2 | 4.3 | Medium | 2017-01-03 | 2009-01-29 | View |
Page 15029 of 17672, showing 5 records out of 88360 total, starting on record 75141, ending on 75145