NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
4316  CVE-2008-4493  Microsoft PicturePusher ActiveX control (PipPPush.DLL 7.00.0709), as used in Microsoft Digital Image 2006 Starter Edition, allows remote attackers to force the upload of arbitrary files by using the AddString and Post methods and a modified PostURL to construct an HTTP POST request. NOTE: this issue might only be exploitable in limited environments or non-default browser settings.    6.8  Medium  2017-01-03  2009-01-29  View
4572  CVE-2008-4758  Directory traversal vulnerability in download_file.php in PHP-Daily allows remote attackers to read arbitrary local files via a .. (dot dot) in the fichier parameter.    Medium  2017-01-03  2009-01-29  View
5340  CVE-2008-5591  Cross-site scripting (XSS) vulnerability in login.asp in Nightfall Personal Diary 1.0 allows remote attackers to inject arbitrary web script or HTML via the username parameter and possibly other "login fields." NOTE: some of these details are obtained from third party information.    4.3  Medium  2017-01-03  2009-01-29  View
3293  CVE-2008-3412  SQL injection vulnerability in Comsenz EPShop (aka ECShop) before 3.0 allows remote attackers to execute arbitrary SQL commands via the pid parameter in a (1) pro_show or (2) disppro action to the default URI.    7.5  High  2017-01-03  2009-01-29  View
3805  CVE-2008-3943  SQL injection vulnerability in listtest.php in eZoneScripts Living Local 1.1 allows remote attackers to execute arbitrary SQL commands via the r parameter.    7.5  High  2017-01-03  2009-01-29  View

Page 15063 of 17672, showing 5 records out of 88360 total, starting on record 75311, ending on 75315

Actions