NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 1952 | CVE-2008-2016 | PHP remote file inclusion vulnerability in Chilek Content Management System (aka ChiCoMaS) 2.0.4 allows remote attackers to execute arbitrary PHP code via a URL in the lang parameter to the default URI under install/. NOTE: this can also be leveraged to include and execute arbitrary local files via directory traversal sequences. | 2 | 7.5 | High | 2017-01-03 | 2009-01-29 | View | |
| 3232 | CVE-2008-3351 | SQL injection vulnerability in atomPhotoBlog.php in Atom PhotoBlog 1.0.9.1 and 1.1.5b1 allows remote attackers to execute arbitrary SQL commands via the photoId parameter in a show action. | 2 | 7.5 | High | 2017-01-03 | 2009-01-29 | View | |
| 5280 | CVE-2008-5531 | Fortinet Antivirus 3.113.0.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit. | 2 | 9.3 | High | 2017-01-03 | 2009-01-29 | View | |
| 1697 | CVE-2008-1757 | Cross-site scripting (XSS) vulnerability in index.php in the ConcoursPhoto module for KwsPHP 1.0 allows remote attackers to inject arbitrary web script or HTML via the VIEW parameter. | 2 | 4.3 | Medium | 2017-01-03 | 2009-01-29 | View | |
| 1953 | CVE-2008-2017 | Directory traversal vulnerability in Chilek Content Management System (aka ChiCoMaS) 2.0.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the operation parameter to the default URI under install/. | 2 | 7.5 | High | 2017-01-03 | 2009-01-29 | View |
Page 15033 of 17672, showing 5 records out of 88360 total, starting on record 75161, ending on 75165