NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
4351 | CVE-2008-4528 | Directory traversal vulnerability in notes.php in Phlatline"s Personal Information Manager (pPIM) 1.01 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the id parameter in an edit action. | 2 | 7.5 | High | 2017-01-03 | 2009-01-29 | View | |
4607 | CVE-2008-4793 | The node module API in Drupal 5.x before 5.11 allows remote attackers to bypass node validation and have unspecified other impact via unknown vectors related to contributed modules. | 2 | 7.5 | High | 2017-01-03 | 2009-08-19 | View | |
70143 | CVE-2005-4554 | Multiple SQL injection vulnerabilities in DEV web management system 1.5 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cat parameter in an openforum action (openforum.php) in index.php, (2) cat parameter in getfile.php, and (3) target parameter in download_now.php. | 2 | 7.5 | High | 2017-01-03 | 2008-09-05 | View | |
5375 | CVE-2008-5633 | SQL injection vulnerability in register.asp in ActiveVotes 2.2 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters, possibly related to start.asp. NOTE: some of these details are obtained from third party information. | 2 | 7.5 | High | 2017-01-03 | 2009-08-15 | View | |
5631 | CVE-2008-5900 | CodeAvalanche Articles stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing the administrator password via a direct request for _private/CAArticles.mdb. NOTE: some of these details are obtained from third party information. | 2 | 7.5 | High | 2017-01-03 | 2009-01-29 | View |
Page 17298 of 17672, showing 5 records out of 88360 total, starting on record 86486, ending on 86490