NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
5850  CVE-2008-6119  Static code injection vulnerability in gooplecms/admin/account/action/editpass.php in Goople CMS 1.7 allows remote attackers to inject arbitrary PHP code into admin/userandpass.php via the (1) username and (2) password parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.    7.5  High  2017-01-03  2009-08-15  View
6106  CVE-2008-6375  JBook stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request to userids.mdb.    Medium  2017-01-03  2009-07-22  View
6362  CVE-2008-6631  Multiple cross-site scripting (XSS) vulnerabilities in index.php in BlogPHP 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) user parameter in a sendmessage action and the (2) username parameter when registering a new user, different vectors than CVE-2008-0679.    4.3  Medium  2017-01-03  2009-08-19  View
6618  CVE-2008-6887  SQL injection vulnerability in detailad.asp in Pre Classified Listings 1.0 allows remote attackers to execute arbitrary SQL commands via the siteid parameter.    7.5  High  2017-01-03  2009-08-03  View
6874  CVE-2008-7143  phpBB 2.0.23 includes the session ID in a request to modcp.php when the moderator or administrator closes a thread, which allows remote attackers to hijack the session via a post in the thread containing a URL to a remotely hosted image, which might include the session ID in the Referer header.    6.8  Medium  2017-01-03  2009-09-09  View

Page 15836 of 17672, showing 5 records out of 88360 total, starting on record 79176, ending on 79180

Actions