NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 5540 | CVE-2008-5800 | SQL injection vulnerability in the Wir ber uns [sic] (fsmi_people) extension 0.0.24 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | 2 | 7.5 | High | 2017-01-03 | 2009-08-13 | View | |
| 5796 | CVE-2008-6065 | Oracle Database Server 10.1, 10.2, and 11g grants directory WRITE permissions for arbitrary pathnames that are aliased in a CREATE OR REPLACE DIRECTORY statement, which allows remote authenticated users with CREATE ANY DIRECTORY privileges to gain SYSDBA privileges by aliasing the pathname of the password directory, and then overwriting the password file through UTL_FILE operations, a related issue to CVE-2006-7141. | 2 | 5.1 | Medium | 2017-01-03 | 2009-03-13 | View | |
| 6052 | CVE-2008-6321 | CF Shopkart 5.2.2 stores cfshopkart52.mdb under the web root with insufficient access control, which allows remote attackers to obtain sensitive information, such as usernames and passwords, via a direct request. | 2 | 5 | Medium | 2017-01-03 | 2009-02-27 | View | |
| 6308 | CVE-2008-6577 | Nortel MG1000S, Signaling Server, and Call Server on the Communications Server 1000 (CS1K) 4.50.x contain multiple unspecified hard-coded accounts and passwords, which allows remote attackers to gain privileges. | 2 | 10 | High | 2017-01-03 | 2009-04-18 | View | |
| 6564 | CVE-2008-6833 | Directory traversal vulnerability in commsrss.php in fuzzylime (cms) before 3.01b allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in a files array element for a blogs action, as demonstrated by the files[0] parameter. | 2 | 10 | High | 2017-01-03 | 2009-08-13 | View |
Page 15361 of 17672, showing 5 records out of 88360 total, starting on record 76801, ending on 76805