NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
6924  CVE-2008-7193  PHPKIT 1.6.4 PL1 includes the session ID in the URL, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks by reading the PHPKITSID parameter from the HTTP Referer and using it in a request to (1) modify the user profile via upload_files/include.php or (2) create a new administrator via upload_files/pk/include.php.    6.8  Medium  2017-01-03  2009-09-10  View
73228  CVE-2003-0081  Format string vulnerability in packet-socks.c of the SOCKS dissector for Ethereal 0.8.7 through 0.9.9 allows remote attackers to execute arbitrary code via SOCKS packets containing format string specifiers.    7.5  High  2017-01-03  2008-09-05  View
74508  CVE-2003-1438  Race condition in BEA WebLogic Server and Express 5.1 through 7.0.0.1, when using in-memory session replication or replicated stateful session beans, causes the same buffer to be provided to two users, which could allow one user to see session data that was intended for another user.    4.3  Medium  2017-01-03  2008-09-05  View
13  CVE-2008-0013  Heap-based buffer overflow in an unspecified procedure in Trend Micro ServerProtect 5.7 and 5.58 allows remote attackers to execute arbitrary code via unknown vectors, possibly related to the product"s configuration, a different vulnerability than CVE-2008-0012 and CVE-2008-0014.    10  High  2017-01-03  2012-10-30  View
269  CVE-2008-0284  Cross-site scripting (XSS) vulnerability in Simple Machines Forum (SMF) 1.1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via (1) Itemid or (2) topic arguments.    4.3  Medium  2017-01-03  2009-09-15  View

Page 1618 of 17672, showing 5 records out of 88360 total, starting on record 8086, ending on 8090

Actions