NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
3067  CVE-2008-3184  Multiple cross-site scripting (XSS) vulnerabilities in vBulletin 3.6.10 PL2 and earlier, and 3.7.2 and earlier 3.7.x versions, allow remote attackers to inject arbitrary web script or HTML via (1) the PATH_INFO (PHP_SELF) or (2) the do parameter, as demonstrated by requests to upload/admincp/faq.php. NOTE: this issue can be leveraged to execute arbitrary PHP code.    4.3  Medium  2017-01-03  2009-01-29  View
4347  CVE-2008-4524  SQL injection vulnerability in the "Check User" feature (includes/check_user.php) in AdaptCMS Lite and AdaptCMS Pro 1.3 allows remote attackers to execute arbitrary SQL commands via the user_name parameter.    7.5  High  2017-01-03  2009-01-29  View
4859  CVE-2008-5072  vsfilter.dll in K-Lite Mega Codec Pack 3.5.7.0 allows remote attackers to cause a denial of service (application crash) via a malformed FLV file.    4.3  Medium  2017-01-03  2009-01-29  View
5627  CVE-2008-5896  CodeAvalanche RateMySite stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing the administrator password via a direct request for _private/CARateMySite.mdb. NOTE: some of these details are obtained from third party information.    7.5  High  2017-01-03  2009-01-29  View
2044  CVE-2008-2110  Unrestricted file upload vulnerability in qtofm.php in QTOFileManager 1.0 allows remote attackers to execute arbitrary PHP code by uploading a file with an executable extension, then accessing it via a direct request.    7.5  High  2017-01-03  2009-01-29  View

Page 15081 of 17672, showing 5 records out of 88360 total, starting on record 75401, ending on 75405

Actions