NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 5672 | CVE-2008-5941 | Cross-site request forgery (CSRF) vulnerability in MODx 0.9.6.1p2 and earlier allows remote attackers to perform unauthorized actions as other users via unknown vectors. | 2 | 6 | Medium | 2017-01-03 | 2009-01-22 | View | |
| 5928 | CVE-2008-6197 | SQL injection vulnerability in index.php in the galerie module for KwsPHP 1.3.456 allows remote attackers to execute arbitrary SQL commands via the id_gal parameter in a gal action. | 2 | 7.5 | High | 2017-01-03 | 2009-02-20 | View | |
| 6184 | CVE-2008-6453 | Directory traversal vulnerability in section.php in 6rbScript 3.3, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the name parameter. | 2 | 4.3 | Medium | 2017-01-03 | 2009-08-19 | View | |
| 6440 | CVE-2008-6709 | Unspecified vulnerability in the Web management interface in Avaya SIP Enablement Services (SES) 3.x and 4.0, as used with Avaya Communication Manager 3.1.x, allows remote authenticated users to execute arbitrary commands via unknown vectors related to configuration of "local data viewing or restoring parameters." | 2 | 9 | High | 2017-01-03 | 2009-08-19 | View | |
| 6696 | CVE-2008-6965 | AJ Square AJ Auction OOPD, Pro Platinum Skin #1, Pro Platinum Skin #2, and Web 2.0 send a redirect but do not exit when certain scripts are called directly, which allows remote attackers to bypass authentication via a direct request to (1) site.php, (2) auction.php, (3) mail.php, (4) fee_setting.php, (5) earnings.php, (6) insertion_fee_settings.php, (7) custom_category.php, (8) subcategory.php, (9) category.php, (10) report.php, (11) store_manager.php, and (12) choose_sell_format.php in admin/, and possibly other vectors. | 2 | 7.5 | High | 2017-01-03 | 2009-08-13 | View |
Page 2414 of 17672, showing 5 records out of 88360 total, starting on record 12066, ending on 12070