NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
776 | CVE-2008-0805 | Unrestricted file upload vulnerability in image.php in PHPizabi 0.848b C1 HFP1 allows remote attackers to execute arbitrary code by uploading a file with an executable extension from the event page, then accessing it via a direct request to the file in system/cache/pictures. | 2 | 9.3 | High | 2017-01-03 | 2011-03-07 | View | |
777 | CVE-2008-0806 | wyrd 1.4.3b allows local users to overwrite arbitrary files via a symlink attack on the wyrd-tmp.[USERID] temporary file. | 2 | 3.6 | Low | 2017-01-03 | 2008-09-05 | View | |
778 | CVE-2008-0807 | lib/Driver/sql.php in Turba 2 (turba2) Contact Manager H3 2.1.x before 2.1.7 and 2.2.x before 2.2-RC3, as used in products such as Horde Groupware before 1.0.4 and Horde Groupware Webmail Edition before 1.0.5, does not properly check access rights, which allows remote authenticated users to modify address data via a modified object_id parameter to edit.php, as demonstrated by modifying a personal address book entry when there is write access to a shared address book. | 2 | 4.9 | Medium | 2017-01-03 | 2011-03-07 | View | |
779 | CVE-2008-0808 | Cross-site scripting (XSS) vulnerability in the meta plugin in Ikiwiki before 1.1.47 allows remote attackers to inject arbitrary web script or HTML via meta tags. | 2 | 4.3 | Medium | 2017-01-03 | 2008-09-05 | View | |
780 | CVE-2008-0809 | Cross-site scripting (XSS) vulnerability in the htmlscrubber in Ikiwiki before 1.1.46 allows remote attackers to inject arbitrary web script or HTML via title contents. | 2 | 4.3 | Medium | 2017-01-03 | 2008-09-05 | View |
Page 156 of 17672, showing 5 records out of 88360 total, starting on record 776, ending on 780