NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 4316 | CVE-2008-4493 | Microsoft PicturePusher ActiveX control (PipPPush.DLL 7.00.0709), as used in Microsoft Digital Image 2006 Starter Edition, allows remote attackers to force the upload of arbitrary files by using the AddString and Post methods and a modified PostURL to construct an HTTP POST request. NOTE: this issue might only be exploitable in limited environments or non-default browser settings. | 2 | 6.8 | Medium | 2017-01-03 | 2009-01-29 | View | |
| 4572 | CVE-2008-4758 | Directory traversal vulnerability in download_file.php in PHP-Daily allows remote attackers to read arbitrary local files via a .. (dot dot) in the fichier parameter. | 2 | 5 | Medium | 2017-01-03 | 2009-01-29 | View | |
| 5340 | CVE-2008-5591 | Cross-site scripting (XSS) vulnerability in login.asp in Nightfall Personal Diary 1.0 allows remote attackers to inject arbitrary web script or HTML via the username parameter and possibly other "login fields." NOTE: some of these details are obtained from third party information. | 2 | 4.3 | Medium | 2017-01-03 | 2009-01-29 | View | |
| 3293 | CVE-2008-3412 | SQL injection vulnerability in Comsenz EPShop (aka ECShop) before 3.0 allows remote attackers to execute arbitrary SQL commands via the pid parameter in a (1) pro_show or (2) disppro action to the default URI. | 2 | 7.5 | High | 2017-01-03 | 2009-01-29 | View | |
| 3805 | CVE-2008-3943 | SQL injection vulnerability in listtest.php in eZoneScripts Living Local 1.1 allows remote attackers to execute arbitrary SQL commands via the r parameter. | 2 | 7.5 | High | 2017-01-03 | 2009-01-29 | View |
Page 15063 of 17672, showing 5 records out of 88360 total, starting on record 75311, ending on 75315