NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
5860 | CVE-2008-6129 | Directory traversal vulnerability in print.php in moziloWiki 1.0.1 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter. | 2 | 4.3 | Medium | 2017-01-03 | 2009-08-19 | View | |
6116 | CVE-2008-6385 | Cross-site scripting (XSS) vulnerability in index.php in W3matter RevSense 1.0 allows remote attackers to inject arbitrary web script or HTML via the section parameter. | 2 | 4.3 | Medium | 2017-01-03 | 2009-05-14 | View | |
6372 | CVE-2008-6641 | Multiple SQL injection vulnerabilities in Shader TV (Beta) allow remote authenticated administrators to execute arbitrary SQL commands via the sid parameter to (1) kanal.asp, (2) google.asp, and (3) hakk.asp in yonet/; and allow remote attackers to execute arbitrary SQL commands via the (4) username or (5) password fields to yonet/default.asp. | 2 | 6.5 | Medium | 2017-01-03 | 2009-04-07 | View | |
6628 | CVE-2008-6897 | Multiple buffer overflows in Getleft.exe in Andres Garcia Getleft 1.2 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long (1) "a" HTML tag; a long src attribute in (2) embed, (3) img, or (4) script tags; (5) a long background attribute in a body tag; and other unspecified tags. | 2 | 9.3 | High | 2017-01-03 | 2009-08-06 | View | |
72164 | CVE-2004-1785 | SQL injection vulnerability in calendar.php for Invision Power Board 1.3 allows remote attackers to execute arbitrary SQL commands via the m parameter, which sets the $this->chosen_month variable. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View |
Page 15986 of 17672, showing 5 records out of 88360 total, starting on record 79926, ending on 79930