NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
5376  CVE-2008-5634  SQL injection vulnerability in account.asp in Active Force Matrix 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters, possibly related to start.asp. NOTE: some of these details are obtained from third party information.    7.5  High  2017-01-03  2009-08-15  View
5632  CVE-2008-5901  iyzi Forum 1.0 beta 3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing a password via a direct request for db/iyziforum.mdb. NOTE: some of these details are obtained from third party information.    7.5  High  2017-01-03  2009-01-29  View
5888  CVE-2008-6157  SepCity Classified Ads stores the admin password in cleartext in data/classifieds.mdb, which allows context-dependent attackers to obtain sensitive information.    Medium  2017-01-03  2009-03-04  View
6144  CVE-2008-6413  Cross-site scripting (XSS) vulnerability in the Answers module 5.x-1.x-dev and possibly other 5.x versions, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via a Simple Answer to a question.    4.3  Medium  2017-01-03  2009-08-19  View
6400  CVE-2008-6669  viewrq.php in nweb2fax 0.2.7 and earlier allows remote attackers to execute arbitrary code via shell metacharacters in the var_filename parameter in a (1) tif or (2) pdf format action.    7.5  High  2017-01-03  2009-04-08  View

Page 2211 of 17672, showing 5 records out of 88360 total, starting on record 11051, ending on 11055

Actions