NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
5664 | CVE-2008-5933 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in CMS ISWEB 3.0 allow remote attackers to inject arbitrary web script or HTML via (1) the strcerca parameter (aka the input field for the cerca action) or (2) the id_oggetto parameter. NOTE: some of these details are obtained from third party information. | 2 | 4.3 | Medium | 2017-01-03 | 2009-01-29 | View | |
5920 | CVE-2008-6189 | SQL injection vulnerability in GForge 4.5.19 allows remote attackers to execute arbitrary SQL commands via the offset parameter to (1) new/index.php, (2) news/index.php, and (3) top/topusers.php, which is not properly handled in database-pgsql.php. | 2 | 7.5 | High | 2017-01-03 | 2011-09-21 | View | |
6176 | CVE-2008-6445 | Unspecified vulnerability in YourPlace before 1.0.1 has unknown impact and attack vectors, possibly related to improper authentication and the ability to upload arbitrary PHP code. NOTE: some of these details are obtained from third party information. | 2 | 7.5 | High | 2017-01-03 | 2010-01-08 | View | |
6432 | CVE-2008-6701 | NetScout (formerly Network General) Visualizer V2100 and InfiniStream i1730 do not restrict access to ResourceManager/en_US/domains/add_domain.jsp, which allows remote attackers to gain administrator privileges via a direct request. | 2 | 7.5 | High | 2017-01-03 | 2009-04-13 | View | |
6688 | CVE-2008-6957 | member.php in Crossday Discuz! Board allows remote attackers to reset passwords of arbitrary users via crafted (1) lostpasswd and (2) getpasswd actions, possibly involving predictable generation of the id parameter. | 2 | 7.5 | High | 2017-01-03 | 2009-08-18 | View |
Page 1802 of 17672, showing 5 records out of 88360 total, starting on record 9006, ending on 9010