NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
363  CVE-2008-0385  SQL injection vulnerability in server/widgetallocator.php in Urulu 2.1 allows remote attackers to execute arbitrary SQL commands via the connectionId parameter to index.php with (1) statprt/js/request or (2) dyn/js/request in the PATH_INFO.    7.5  High  2017-01-03  2008-09-05  View
65899  CVE-2005-0119  helvis 1.8h2_1 and earlier allows local users to recover and read the files of other users via the elvrec setuid program.    2.1  Low  2017-01-03  2008-09-05  View
875  CVE-2008-0905  Directory traversal vulnerability in globsy_edit.php in Globsy 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.    Medium  2017-01-03  2008-09-05  View
66411  CVE-2005-0660  Multiple cross-site scripting (XSS) vulnerabilities in D-Forum 1.11 allows remote attackers to inject arbitrary web script or HTML via certain fields, as demonstrated using the page parameter in nav.php3.    4.3  Medium  2017-01-03  2008-09-05  View
1131  CVE-2008-1171  ** DISPUTED ** Multiple PHP remote file inclusion vulnerabilities in the 123 Flash Chat Module for phpBB allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter to (1) 123flashchat.php and (2) phpbb_login_chat.php. NOTE: CVE disputes this issue because $phpbb_root_path is explicitly set to "./" in both programs.    6.8  Medium  2017-01-03  2008-09-05  View

Page 16670 of 17672, showing 5 records out of 88360 total, starting on record 83346, ending on 83350

Actions