NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
2535 | CVE-2008-2629 | SQL injection vulnerability in the LifeType (formerly pLog) module for Drupal allows remote attackers to execute arbitrary SQL commands via the albumId parameter in a ViewAlbum action to index.php. | 2 | 7.5 | High | 2017-01-03 | 2009-09-09 | View | |
68071 | CVE-2005-2379 | Multiple cross-site scripting (XSS) vulnerabilities in Oracle Reports 9.0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) debug parameter to showenv, (2) test parameter to parsequery, or (3) delimiter or (4) CELLWRAPPER parameter to rwservlet. | 2 | 4.3 | Medium | 2017-01-03 | 2016-10-17 | View | |
2791 | CVE-2008-2897 | SQL injection vulnerability in index.php in PageSquid CMS 0.3 Beta allows remote attackers to execute arbitrary SQL commands via the page parameter. | 2 | 7.5 | High | 2017-01-03 | 2009-04-14 | View | |
68327 | CVE-2005-2638 | Multiple cross-site scripting (XSS) vulnerabilities in PHPFreeNews 1.40 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) NewsMode parameter to NewsCategoryForm.php, or the (2) Match or (3) NewsMode parameter to SearchResults.php. | 2 | 4.3 | Medium | 2017-01-03 | 2016-10-17 | View | |
3047 | CVE-2008-3163 | Directory traversal vulnerability in dodosmail.php in DodosMail 2.5 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the dodosmail_header_file parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | 2 | 6.8 | Medium | 2017-01-03 | 2008-09-05 | View |
Page 15949 of 17672, showing 5 records out of 88360 total, starting on record 79741, ending on 79745