NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
363 | CVE-2008-0385 | SQL injection vulnerability in server/widgetallocator.php in Urulu 2.1 allows remote attackers to execute arbitrary SQL commands via the connectionId parameter to index.php with (1) statprt/js/request or (2) dyn/js/request in the PATH_INFO. | 2 | 7.5 | High | 2017-01-03 | 2008-09-05 | View | |
65899 | CVE-2005-0119 | helvis 1.8h2_1 and earlier allows local users to recover and read the files of other users via the elvrec setuid program. | 2 | 2.1 | Low | 2017-01-03 | 2008-09-05 | View | |
875 | CVE-2008-0905 | Directory traversal vulnerability in globsy_edit.php in Globsy 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter. | 2 | 5 | Medium | 2017-01-03 | 2008-09-05 | View | |
66411 | CVE-2005-0660 | Multiple cross-site scripting (XSS) vulnerabilities in D-Forum 1.11 allows remote attackers to inject arbitrary web script or HTML via certain fields, as demonstrated using the page parameter in nav.php3. | 2 | 4.3 | Medium | 2017-01-03 | 2008-09-05 | View | |
1131 | CVE-2008-1171 | ** DISPUTED ** Multiple PHP remote file inclusion vulnerabilities in the 123 Flash Chat Module for phpBB allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter to (1) 123flashchat.php and (2) phpbb_login_chat.php. NOTE: CVE disputes this issue because $phpbb_root_path is explicitly set to "./" in both programs. | 2 | 6.8 | Medium | 2017-01-03 | 2008-09-05 | View |
Page 16670 of 17672, showing 5 records out of 88360 total, starting on record 83346, ending on 83350