NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
5346 | CVE-2008-5597 | Cold BBS stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for db/cforum.mdb. | 2 | 5 | Medium | 2017-01-03 | 2009-01-29 | View | |
5602 | CVE-2008-5871 | Nortel Multimedia Communication Server (MSC) 5100 3.0.13 does not verify credentials during call placement, which allows remote attackers to spoof and redirect VoIP calls, possibly related to the snoop command. | 2 | 6.4 | Medium | 2017-01-03 | 2011-03-07 | View | |
5858 | CVE-2008-6127 | Multiple cross-site scripting (XSS) vulnerabilities in moziloCMS 1.10.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) page and (2) query parameters to (a) index.php, (3) cat and (4) file parameters to (b) download.php, (5) gal parameter to gallery.php, and the (6) URL to admin/login.php. | 2 | 4.3 | Medium | 2017-01-03 | 2009-08-19 | View | |
6114 | CVE-2008-6383 | SQL injection vulnerability in SpeedTech Organization and Resource Manager (Storm) 5.x before 5.x-1.14 and 6.x before 6.x-1.18, a module for Drupal, allows remote authenticated users with storm project access to execute arbitrary SQL commands via unspecified vectors. | 2 | 6 | Medium | 2017-01-03 | 2009-05-14 | View | |
6370 | CVE-2008-6639 | Cross-site request forgery (CSRF) vulnerability in admin.php in AjaXplorer 2.3.3 and 2.3.4 allows remote attackers to hijack the authentication of administrators for requests that modify passwords via the update_user_pwd action. | 2 | 6.8 | Medium | 2017-01-03 | 2009-04-07 | View |
Page 15864 of 17672, showing 5 records out of 88360 total, starting on record 79316, ending on 79320