NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
5858 | CVE-2008-6127 | Multiple cross-site scripting (XSS) vulnerabilities in moziloCMS 1.10.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) page and (2) query parameters to (a) index.php, (3) cat and (4) file parameters to (b) download.php, (5) gal parameter to gallery.php, and the (6) URL to admin/login.php. | 2 | 4.3 | Medium | 2017-01-03 | 2009-08-19 | View | |
6114 | CVE-2008-6383 | SQL injection vulnerability in SpeedTech Organization and Resource Manager (Storm) 5.x before 5.x-1.14 and 6.x before 6.x-1.18, a module for Drupal, allows remote authenticated users with storm project access to execute arbitrary SQL commands via unspecified vectors. | 2 | 6 | Medium | 2017-01-03 | 2009-05-14 | View | |
6370 | CVE-2008-6639 | Cross-site request forgery (CSRF) vulnerability in admin.php in AjaXplorer 2.3.3 and 2.3.4 allows remote attackers to hijack the authentication of administrators for requests that modify passwords via the update_user_pwd action. | 2 | 6.8 | Medium | 2017-01-03 | 2009-04-07 | View | |
6626 | CVE-2008-6895 | 3CX Phone System 6.0.806.0 allows remote attackers to cause a denial of service (unstable service or crash) via unspecified vectors, as demonstrated by vulnerability scans from Nessus or SAINT. | 2 | 7.8 | High | 2017-01-03 | 2009-08-19 | View | |
6882 | CVE-2008-7151 | Cross-site request forgery (CSRF) vulnerability in Live 5.x before 5.x-0.1, a module for Drupal, allows remote attackers to hijack the authentication of unspecified privileged users for requests that can be leveraged to execute arbitrary PHP code. | 2 | 6.8 | Medium | 2017-01-03 | 2009-09-09 | View |
Page 15908 of 17672, showing 5 records out of 88360 total, starting on record 79536, ending on 79540