NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
2331 | CVE-2008-2415 | Directory traversal vulnerability in template/purpletech/base_include.php in DigitalHive (aka hive) 2.0 RC2 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter. | 2 | 6.8 | Medium | 2017-01-03 | 2008-09-05 | View | |
67867 | CVE-2005-2163 | Cross-site scripting (XSS) vulnerability in index.php in AutoIndex PHP Script 1.5.2 allows remote attackers to inject arbitrary web script or HTML via the search parameter. | 2 | 4.3 | Medium | 2017-01-03 | 2016-10-17 | View | |
2587 | CVE-2008-2689 | PHP remote file inclusion vulnerability in pub/clients.php in BrowserCRM 5.002.00 allows remote attackers to execute arbitrary PHP code via a URL in the bcrm_pub_root parameter. | 2 | 10 | High | 2017-01-03 | 2009-04-08 | View | |
2843 | CVE-2008-2949 | Cross-domain vulnerability in Microsoft Internet Explorer 6 and 7 allows remote attackers to change the location property of a frame via the String data type, and use a frame from a different domain to observe domain-independent events, as demonstrated by observing onkeydown events with caballero-listener. NOTE: according to Microsoft, this is a duplicate of CVE-2008-2947, possibly a different attack vector. | 2 | 6.8 | Medium | 2017-01-03 | 2011-03-07 | View | |
68379 | CVE-2005-2690 | SQL injection vulnerability in the Downloads module in PostNuke 0.760-RC4b allows PostNuke administrators to execute arbitrary SQL commands via the show parameter to dl-viewdownload.php. | 2 | 7.5 | High | 2017-01-03 | 2008-09-05 | View |
Page 1624 of 17672, showing 5 records out of 88360 total, starting on record 8116, ending on 8120