NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
5614 | CVE-2008-5883 | Absolute path traversal vulnerability in front-end/dir.php in mini-pub 0.3 and earlier allows remote attackers to list arbitrary directories via a full pathname in the sDir parameter. | 2 | 7.8 | High | 2017-01-03 | 2009-01-29 | View | |
5870 | CVE-2008-6139 | Directory traversal vulnerability in faqsupport/wce.download.php in WebBiscuits Modules Controller 1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the download parameter. | 2 | 5 | Medium | 2017-01-03 | 2009-08-19 | View | |
6126 | CVE-2008-6395 | The web management interface in 3Com Wireless 8760 Dual Radio 11a/b/g PoE Access Point allows remote attackers to cause a denial of service (device crash) via a malformed HTTP POST request. | 2 | 7.8 | High | 2017-01-03 | 2009-03-13 | View | |
6382 | CVE-2008-6651 | Static code injection vulnerability in edithistory.php in OxYProject OxYBox 0.85 allows remote attackers to inject arbitrary PHP code into oxyhistory.php via the oxymsg parameter. | 2 | 10 | High | 2017-01-03 | 2009-04-07 | View | |
6638 | CVE-2008-6907 | Multiple SQL injection vulnerabilities in checkuser.php in 2532designs 2532|Gigs 1.2.2 Stable, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters, as accessible from a form generated by index.php. | 2 | 6.8 | Medium | 2017-01-03 | 2009-08-06 | View |
Page 16018 of 17672, showing 5 records out of 88360 total, starting on record 80086, ending on 80090