NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
70346  CVE-2005-4757  BEA WebLogic Server and WebLogic Express 8.1 SP3 and earlier, and 7.0 SP5 and earlier, do not properly "constrain" a "/" (slash) servlet root URL pattern, which might allow remote attackers to bypass intended servlet protections.    7.5  High  2017-01-03  2008-09-05  View
5066  CVE-2008-5288  PHP remote file inclusion vulnerability in include/header.php in Werner Hilversum FAQ Manager 1.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the config_path parameter.    6.8  Medium  2017-01-03  2009-08-15  View
5322  CVE-2008-5573  SQL injection vulnerability in the login feature in Poll Pro 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) Password and (2) username parameters.    7.5  High  2017-01-03  2009-03-18  View
5578  CVE-2008-5847  Constructr CMS 3.02.5 and earlier stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain sensitive information by reading the hash column.    2.6  Low  2017-01-03  2009-01-29  View
5834  CVE-2008-6103  PHP remote file inclusion vulnerability in index.php in A4Desk Event Calendar, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary PHP code via a URL in the v parameter.    6.8  Medium  2017-01-03  2009-02-11  View

Page 15696 of 17672, showing 5 records out of 88360 total, starting on record 78476, ending on 78480

Actions