NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
5008  CVE-2008-5224  Cross-site scripting (XSS) vulnerability in Kent Web Mart 1.61 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.    4.3  Medium  2017-01-03  2009-04-01  View
5264  CVE-2008-5515  Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, 6.0.0 through 6.0.18, and possibly earlier versions normalizes the target pathname before filtering the query string when using the RequestDispatcher method, which allows remote attackers to bypass intended access restrictions and conduct directory traversal attacks via .. (dot dot) sequences and the WEB-INF directory in a Request.    Medium  2017-01-03  2016-08-22  View
5520  CVE-2008-5780  Forest Blog 1.3.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing passwords via a direct request for blog.mdb.    Medium  2017-01-03  2009-01-29  View
5776  CVE-2008-6045  Session fixation vulnerability in shopping_cart.php in xt:Commerce 3.0.4 and earlier allows remote attackers to hijack web sessions by setting the XTCsid parameter.    6.8  Medium  2017-01-03  2009-08-19  View
6032  CVE-2008-6301  SQL injection vulnerability in shoutbox_view.php in the Small ShoutBox module 1.4 for phpBB allows remote attackers to execute arbitrary SQL commands via the id parameter in a delete action.    7.5  High  2017-01-03  2009-03-13  View

Page 15185 of 17672, showing 5 records out of 88360 total, starting on record 75921, ending on 75925

Actions