NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
5656 | CVE-2008-5925 | ASP-DEv XM Events Diary stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for diary.mdb. | 2 | 5 | Medium | 2017-01-03 | 2009-01-23 | View | |
5912 | CVE-2008-6181 | SQL injection vulnerability in the Mad4Joomla Mailforms (com_mad4joomla) component before 1.1.8.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the jid parameter to index.php. | 2 | 7.5 | High | 2017-01-03 | 2009-02-20 | View | |
6168 | CVE-2008-6437 | Multiple cross-site scripting (XSS) vulnerabilities in PHPFreeForum 1.0 RC2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) message parameter to error.php, and the (2) nickname and (3) randomid parameters to part/menu.php. | 2 | 4.3 | Medium | 2017-01-03 | 2009-04-02 | View | |
6424 | CVE-2008-6693 | SQL injection vulnerability in Download system (sb_downloader) extension 0.1.4 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unknown vectors. | 2 | 7.5 | High | 2017-01-03 | 2009-08-20 | View | |
6680 | CVE-2008-6949 | Multiple cross-site request forgery (CSRF) vulnerabilities in Collabtive 0.4.8 allow remote attackers to hijack the authentication of administrators for requests that (1) submit or edit a new project, or (2) upload files to a project, or (3) attach files to messages via unknown vectors. NOTE: these issues can be leveraged with other vulnerabilities to create remote attack vectors that do not require authentication. | 2 | 6.8 | Medium | 2017-01-03 | 2009-08-12 | View |
Page 1727 of 17672, showing 5 records out of 88360 total, starting on record 8631, ending on 8635