NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
3360 | CVE-2008-3487 | SQL injection vulnerability in profile.php in PHPAuction GPL Enhanced 2.51 allows remote attackers to execute arbitrary SQL commands via the id parameter. | 2 | 7.5 | High | 2017-01-03 | 2009-01-29 | View | |
3359 | CVE-2008-3486 | Directory traversal vulnerability in the user_get_profile function in include/functions.inc.php in Coppermine Photo Gallery (CPG) 1.4.18 and earlier, when the charset is utf-8, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang part of serialized data in an _data cookie. | 2 | 7.5 | High | 2017-01-03 | 2009-08-19 | View | |
3358 | CVE-2008-3485 | Untrusted search path vulnerability in Citrix MetaFrame Presentation Server allows local users to gain privileges via a malicious icabar.exe placed in the search path. | 2 | 7.2 | High | 2017-01-03 | 2009-01-29 | View | |
3357 | CVE-2008-3484 | SQL injection vulnerability in eStoreAff 0.1 allows remote attackers to execute arbitrary SQL commands via the cid parameter in a showcat action to index.php. | 2 | 7.5 | High | 2017-01-03 | 2009-01-29 | View | |
3356 | CVE-2008-3483 | Cross-site scripting (XSS) vulnerability in ScrewTurn Wiki 2.0.29 and 2.0.30 allows remote attackers to inject arbitrary web script or HTML via error messages in the "/admin.aspx - System Log" page. | 2 | 4.3 | Medium | 2017-01-03 | 2009-04-14 | View |
Page 17001 of 17672, showing 5 records out of 88360 total, starting on record 85001, ending on 85005