NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
2331  CVE-2008-2415  Directory traversal vulnerability in template/purpletech/base_include.php in DigitalHive (aka hive) 2.0 RC2 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter.    6.8  Medium  2017-01-03  2008-09-05  View
67867  CVE-2005-2163  Cross-site scripting (XSS) vulnerability in index.php in AutoIndex PHP Script 1.5.2 allows remote attackers to inject arbitrary web script or HTML via the search parameter.    4.3  Medium  2017-01-03  2016-10-17  View
2587  CVE-2008-2689  PHP remote file inclusion vulnerability in pub/clients.php in BrowserCRM 5.002.00 allows remote attackers to execute arbitrary PHP code via a URL in the bcrm_pub_root parameter.    10  High  2017-01-03  2009-04-08  View
2843  CVE-2008-2949  Cross-domain vulnerability in Microsoft Internet Explorer 6 and 7 allows remote attackers to change the location property of a frame via the String data type, and use a frame from a different domain to observe domain-independent events, as demonstrated by observing onkeydown events with caballero-listener. NOTE: according to Microsoft, this is a duplicate of CVE-2008-2947, possibly a different attack vector.    6.8  Medium  2017-01-03  2011-03-07  View
68379  CVE-2005-2690  SQL injection vulnerability in the Downloads module in PostNuke 0.760-RC4b allows PostNuke administrators to execute arbitrary SQL commands via the show parameter to dl-viewdownload.php.    7.5  High  2017-01-03  2008-09-05  View

Page 1624 of 17672, showing 5 records out of 88360 total, starting on record 8116, ending on 8120

Actions