NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
2536 | CVE-2008-2630 | SQL injection vulnerability in the JooBlog (com_jb2) component 0.1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the CategoryID parameter in a category action to index.php. | 2 | 7.5 | High | 2017-01-03 | 2011-03-07 | View | |
68072 | CVE-2005-2380 | Multiple cross-site scripting vulnerabilities in PHP Surveyor 0.98 allow remote attackers to inject arbitrary web script or HTML via the (1) sid, (2) start, and (3) id parameters to browse.php, or the sid parameter to (4) dataentry.php or (5) export.php. | 2 | 5 | Medium | 2017-01-03 | 2016-10-17 | View | |
2792 | CVE-2008-2898 | Directory traversal vulnerability in includes/header.php in Hedgehog-CMS 1.21 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the c_temp_path parameter. NOTE: in some environments, this can be leveraged for remote file inclusion by using a UNC share pathname or an ftp, ftps, or ssh2.sftp URL. | 2 | 9.3 | High | 2017-01-03 | 2009-04-14 | View | |
68328 | CVE-2005-2639 | Buffer overflow in Chris Moneymaker"s World Poker Championship 1.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long nickname. | 2 | 7.5 | High | 2017-01-03 | 2016-10-17 | View | |
3048 | CVE-2008-3164 | Directory traversal vulnerability in blog.php in fuzzylime (cms) 3.01, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the file parameter. NOTE: it was later reported that 3.01a is also affected. | 2 | 7.6 | High | 2017-01-03 | 2011-03-07 | View |
Page 16223 of 17672, showing 5 records out of 88360 total, starting on record 81111, ending on 81115