NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
2536  CVE-2008-2630  SQL injection vulnerability in the JooBlog (com_jb2) component 0.1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the CategoryID parameter in a category action to index.php.    7.5  High  2017-01-03  2011-03-07  View
68072  CVE-2005-2380  Multiple cross-site scripting vulnerabilities in PHP Surveyor 0.98 allow remote attackers to inject arbitrary web script or HTML via the (1) sid, (2) start, and (3) id parameters to browse.php, or the sid parameter to (4) dataentry.php or (5) export.php.    Medium  2017-01-03  2016-10-17  View
2792  CVE-2008-2898  Directory traversal vulnerability in includes/header.php in Hedgehog-CMS 1.21 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the c_temp_path parameter. NOTE: in some environments, this can be leveraged for remote file inclusion by using a UNC share pathname or an ftp, ftps, or ssh2.sftp URL.    9.3  High  2017-01-03  2009-04-14  View
68328  CVE-2005-2639  Buffer overflow in Chris Moneymaker"s World Poker Championship 1.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long nickname.    7.5  High  2017-01-03  2016-10-17  View
3048  CVE-2008-3164  Directory traversal vulnerability in blog.php in fuzzylime (cms) 3.01, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the file parameter. NOTE: it was later reported that 3.01a is also affected.    7.6  High  2017-01-03  2011-03-07  View

Page 16223 of 17672, showing 5 records out of 88360 total, starting on record 81111, ending on 81115

Actions