NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 3830 | CVE-2008-3968 | Cross-site scripting (XSS) vulnerability in userlist.php in PunBB before 1.2.20 allows remote attackers to inject arbitrary web script or HTML via the p parameter. | 2 | 4.3 | Medium | 2017-01-03 | 2008-10-18 | View | |
| 1949 | CVE-2008-2013 | SQL injection vulnerability in index.php in the pnFlashGames 1.5 through 2.5 module for PostNuke, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter in a display action. | 2 | 6.8 | Medium | 2017-01-03 | 2008-10-16 | View | |
| 4158 | CVE-2008-4330 | Directory traversal vulnerability in index.php in LanSuite 3.3.2 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the design parameter. | 2 | 7.5 | High | 2017-01-03 | 2008-10-15 | View | |
| 1293 | CVE-2008-1334 | cgi/b on the BT Home Hub router allows remote attackers to bypass authentication, and read or modify administrative settings or make arbitrary VoIP telephone calls, by placing a character at the end of the PATH_INFO, as demonstrated by (1) %5C (encoded backslash), (2) "%" (percent), and (3) "~" (tilde). NOTE: the "/" (slash) vector is already covered by CVE-2007-5383. | 2 | 7.5 | High | 2017-01-03 | 2008-10-11 | View | |
| 547 | CVE-2008-0572 | Multiple PHP remote file inclusion vulnerabilities in Mindmeld 1.2.0.10 allow remote attackers to execute arbitrary PHP code via a URL in the MM_GLOBALS[home] parameter to (1) acweb/admin_index.php; and (2) ask.inc.php, (3) learn.inc.php, (4) manage.inc.php, (5) mind.inc.php, and (6) sensory.inc.php in include/. | 2 | 6.8 | Medium | 2017-01-03 | 2008-10-11 | View |
Page 15474 of 17672, showing 5 records out of 88360 total, starting on record 77366, ending on 77370