NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 6265 | CVE-2008-6534 | Incomplete blacklist vulnerability in NULL FTP Server Free and Pro 1.1.0.7 allows remote authenticated users to execute arbitrary commands via a custom SITE command containing shell metacharacters such as "&" (ampersand) in the middle of an argument. | 2 | 7.1 | High | 2017-01-03 | 2009-03-27 | View | |
| 6264 | CVE-2008-6533 | Drupal 5.x before 5.13 and 6.x before 6.7 does not delete all related content when an input format is deleted, which prevents the content from being properly filtered and allows remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors. | 2 | 4.3 | Medium | 2017-01-03 | 2009-04-25 | View | |
| 6263 | CVE-2008-6532 | Multiple cross-site request forgery (CSRF) vulnerabilities in the update feature in Drupal 5.x before 5.13 and 6.x before 6.7 allow remote attackers to perform unauthorized actions as the superuser via unspecified vectors, as demonstrated by causing the superuser to "execute old updates" that modify the database. | 2 | 6.8 | Medium | 2017-01-03 | 2009-04-25 | View | |
| 6262 | CVE-2008-6531 | The WebWork 1 web application framework in Atlassian JIRA before 3.13.2 allows remote attackers to invoke exposed public JIRA methods via a crafted URL that is dynamically transformed into method calls, aka "WebWork 1 Parameter Injection Hole." | 2 | 6.8 | Medium | 2017-01-03 | 2009-03-27 | View | |
| 6261 | CVE-2008-6530 | Unrestricted file upload vulnerability in editimage.php in eZoneScripts Living Local 1.1 allows remote authenticated administrators to execute arbitrary PHP code by uploading a file with an executable extension, then accessing it via a direct request to the uploaded file. | 2 | 6.5 | Medium | 2017-01-03 | 2009-03-26 | View |
Page 16420 of 17672, showing 5 records out of 88360 total, starting on record 82096, ending on 82100