NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
5380 | CVE-2008-5638 | Multiple SQL injection vulnerabilities in Active Price Comparison 4 allow remote attackers to execute arbitrary SQL commands via the (1) ProductID parameter to reviews.aspx or the (2) linkid parameter to links.asp. | 2 | 7.5 | High | 2017-01-03 | 2009-08-15 | View | |
5636 | CVE-2008-5905 | The web interface plugin in KTorrent before 3.1.4 allows remote attackers to bypass intended access restrictions and upload arbitrary torrent files, and trigger the start of downloads and seeding, via a crafted HTTP POST request. | 2 | 4.3 | Medium | 2017-01-03 | 2009-05-09 | View | |
5892 | CVE-2008-6161 | Cross-site scripting (XSS) vulnerability in WOW Raid Manager (WRM) before 3.5.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 2 | 4.3 | Medium | 2017-01-03 | 2009-02-19 | View | |
6148 | CVE-2008-6417 | Unspecified vulnerability in GreenSQL-Console before 0.3.5 allows attackers to obtain the "installation directory" via unknown vectors. | 2 | 5 | Medium | 2017-01-03 | 2009-04-02 | View | |
6404 | CVE-2008-6673 | asp/bs_login.asp in QuickerSite 1.8.5 does not properly restrict access to administrative functionality, which allows remote attackers to (1) change the admin password via the cSaveAdminPW action; (2) modify site information, such as the contact address, via the saveAdmin; and (3) modify the site design via the saveDesign action. | 2 | 7.5 | High | 2017-01-03 | 2009-04-23 | View |
Page 249 of 17672, showing 5 records out of 88360 total, starting on record 1241, ending on 1245