NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
5625  CVE-2008-5894  Directory traversal vulnerability in index.php in Mediatheka 4.2 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter.    6.8  Medium  2017-01-03  2009-01-29  View
1786  CVE-2008-1846  The default configuration of SAP NetWeaver before 7.0 SP15 does not enable the "Always Use Secure HTML Editor" (aka Editor Security or Secure Editing) parameter, which allows remote attackers to conduct cross-site scripting (XSS) attacks by entering feedback for a file.    4.3  Medium  2017-01-03  2009-01-29  View
2810  CVE-2008-2916  Multiple SQL injection vulnerabilities in Pre ADS Portal 2.0 and earlier, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) cid parameter to showcategory.php and the (2) id parameter to software-description.php.    6.8  Medium  2017-01-03  2009-01-29  View
4346  CVE-2008-4523  SQL injection vulnerability in login.php in IP Reg 0.4 and earlier allows remote attackers to execute arbitrary SQL commands via the user_name parameter.    7.5  High  2017-01-03  2009-01-29  View
5626  CVE-2008-5895  SQL injection vulnerability in connection.php in Mediatheka 4.2 and earlier allows remote attackers to execute arbitrary SQL commands via the user parameter.    7.5  High  2017-01-03  2009-01-29  View

Page 15080 of 17672, showing 5 records out of 88360 total, starting on record 75396, ending on 75400

Actions