NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
3830  CVE-2008-3968  Cross-site scripting (XSS) vulnerability in userlist.php in PunBB before 1.2.20 allows remote attackers to inject arbitrary web script or HTML via the p parameter.    4.3  Medium  2017-01-03  2008-10-18  View
1949  CVE-2008-2013  SQL injection vulnerability in index.php in the pnFlashGames 1.5 through 2.5 module for PostNuke, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter in a display action.    6.8  Medium  2017-01-03  2008-10-16  View
4158  CVE-2008-4330  Directory traversal vulnerability in index.php in LanSuite 3.3.2 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the design parameter.    7.5  High  2017-01-03  2008-10-15  View
1293  CVE-2008-1334  cgi/b on the BT Home Hub router allows remote attackers to bypass authentication, and read or modify administrative settings or make arbitrary VoIP telephone calls, by placing a character at the end of the PATH_INFO, as demonstrated by (1) %5C (encoded backslash), (2) "%" (percent), and (3) "~" (tilde). NOTE: the "/" (slash) vector is already covered by CVE-2007-5383.    7.5  High  2017-01-03  2008-10-11  View
547  CVE-2008-0572  Multiple PHP remote file inclusion vulnerabilities in Mindmeld 1.2.0.10 allow remote attackers to execute arbitrary PHP code via a URL in the MM_GLOBALS[home] parameter to (1) acweb/admin_index.php; and (2) ask.inc.php, (3) learn.inc.php, (4) manage.inc.php, (5) mind.inc.php, and (6) sensory.inc.php in include/.    6.8  Medium  2017-01-03  2008-10-11  View

Page 15474 of 17672, showing 5 records out of 88360 total, starting on record 77366, ending on 77370

Actions