NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
5709  CVE-2008-5978  Multiple SQL injection vulnerabilities in Ocean12 Mailing List Manager Gold allow remote attackers to execute arbitrary SQL commands via the Email parameter to (1) default.asp and (2) s_edit.asp.    7.5  High  2017-01-03  2010-06-15  View
5965  CVE-2008-6234  SQL injection vulnerability in the com_musica module in Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.    7.5  High  2017-01-03  2009-02-24  View
6221  CVE-2008-6490  function/update_xml.php in FLABER 1.1 and earlier allows remote attackers to overwrite arbitrary files by specifying the target filename in the target_file parameter. NOTE: this can be leveraged for code execution by overwriting a PHP file, as demonstrated using function/upload_file.php.    7.5  High  2017-01-03  2009-03-19  View
6477  CVE-2008-6746  Cross-site scripting (XSS) vulnerability in the contact display view in Turba Contact Manager H3 before 2.2.1 allows remote attackers to inject arbitrary web script or HTML via the contact name.    4.3  Medium  2017-01-03  2009-04-23  View
6733  CVE-2008-7002  PHP 5.2.5 does not enforce (a) open_basedir and (b) safe_mode_exec_dir restrictions for certain functions, which might allow local users to bypass intended access restrictions and call programs outside of the intended directory via the (1) exec, (2) system, (3) shell_exec, (4) passthru, or (5) popen functions, possibly involving pathnames such as "C:" drive notation.    7.2  High  2017-01-03  2009-08-19  View

Page 2213 of 17672, showing 5 records out of 88360 total, starting on record 11061, ending on 11065

Actions